Malicious NPM -packs Use dishonest back doors to target users


  • Security researchers from turning labs find two malicious packages on NPM
  • These serve as downloaders and target software developers based on Ethereum Blockchain
  • Malware opens a reverse shell and gives attackers access to target computers

Two malicious packages were recently discovered on the NPM depot using questionable back doors to target their users.

CyberSecurity scientists from Reversing Labs discovered two packages that were uploaded to the popular depot in early March 2025 called “Ethers-Provider2”, and “Ethers-Providerz” names that were carefully chosen to fool victims to believe that they have something to do with a legitimate package called “Ethers”.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top