Malicious NPM packages use sneaky drifts to target users


  • Researchers in Reversing Labs safety find two malicious packages on NPM
  • These serve as downloads and target software developers based on Ethereum blockchain
  • Malware opens an inverted shell and grants attackers access to target computers

Two malicious packages were recently discovered on the NPM frame of reference using dubious deadlines to target their users.

The cybersecurity researchers of overturning Labs discovered two packages which were downloaded in the popular benchmark in early March 2025 named “Ethers-Provider2” and “Ethers-Providerz”-names carefully chosen to encourage victims to think that they have something to do with a legitimate package called “Ethers”.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top