eth (1)

Cybercriminals Target Ethereum Developers with Fake Hardhat npm Packages

Teilen:

Cybersecurity researchers have revealed several malicious packages on the npm registry that have been found impersonating the Nomic Foundation’s Hardhat tool in order to steal sensitive data from developer systems.

“By exploiting trust in open source plugins, attackers have infiltrated these platforms through malicious npm packages, exfiltrating critical data such as private keys, mnemonics, and configuration details,” the Socket research team said in an analysis.

Hardhat is a development environment for Ethereum software, incorporating various components for editing, compiling, debugging and deploying smart contracts and decentralized apps (dApps).

The list of identified counterfeit packages is as follows –

  • nomicsfoundations
  • @nomisfoundation/hardhat-configure
  • installedpackagepublish
  • @nomisfoundation/hardhat-config
  • @monicfoundation/hardhat-config
  • @nomicsfoundation/sdk-test
  • @nomicsfoundation/hardhat-config
  • @nomicsfoundation/web3-sdk
  • @nomicsfoundation/sdk-test1
  • @nomicfoundations/hardhat-config
  • crypto-nodes-validator
  • solana-validator
  • node-validators
  • hardhat-deploy-others
  • hardhat-gas-optimizer
  • solidity-comments-extractors

Of these packages, @nomicsfoundation/sdk-test has attracted 1,092 downloads. It was published over a year ago in October 2023. Once installed, they are designed to harvest mnemonic phrases and private keys from the Hardhat environment, following which they are exfiltrated to an attacker-controlled server.

“The attack begins when compromised packages are installed. These packages exploit the Hardhat runtime environment using functions such as hreInit() and hreConfig() to collect sensitive details like private keys, mnemonics, and configuration files,” the company said.

“The collected data is transmitted to attacker-controlled endpoints, leveraging hardcoded keys and Ethereum addresses for streamlined exfiltration.”

The disclosure comes days after the discovery of another malicious npm package named ethereumvulncontracthandler that masquerades as a library for detecting vulnerabilities in Ethereum smart contracts but instead harbored functionality to drop the Quasar RAT malware.

In recent months, malicious npm packages have also been observed using Ethereum smart contracts for command-and-control (C2) server address distribution, co-opting infected machines into a blockchain-powered botnet called MisakaNetwork. The campaign has been tracked back to a Russian-speaking threat actor named “_lain.”

“The threat actor points out an inherent npm ecosystem complexity, where packages often rely on numerous dependencies, creating a complex ‘nesting doll’ structure,” Socket said.

“This dependency chain makes comprehensive security reviews challenging and opens opportunities for attackers to introduce malicious code. _lain admits to exploiting this complexity and dependency sprawl in npm ecosystems, knowing that it is impractical for developers to scrutinize every single package and dependency.”

That’s not all. A set of phony libraries uncovered across the npm, PyPI, and RubyGems ecosystems have been found leveraging out-of-band application security testing (OAST) tools such as oastify.com and oast.fun to exfiltrate sensitive data to attacker-controlled servers.

The names of the packages are as follows –

  • adobe-dcapi-web (npm), which avoids compromising Windows, Linux, and macOS endpoints located in Russia and comes with capabilities to collect system information
  • monoliht (PyPI), which collects system metadata
  • chauuuyhhn, nosvemosssadfsd, holaaaaaafasdf (RubyGems), which contain embedded scripts designed to transfer sensitive information via DNS queries to an oastify.com endpoint

“The same tools and techniques created for ethical security assessments are being misused by threat actors,” Socket researcher Kirill Boychenko said. “Originally intended to uncover vulnerabilities in web applications, OAST methods are increasingly exploited to steal data, establish command and control (C2) channels, and execute multi-stage attacks.”

To mitigate the supply chain risks posed by such packages, it’s recommended that software developers verify package authenticity, exercise caution when typing package names, and inspect the source code before installation.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:24 pm, März 16, 2025
Wetter-Symbol 8°C
L: 8° | H: 10°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 55 %
Druck: 1025 mb
Wind: 10 mph NE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 6:12 am
Sonnenuntergang: 6:06 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
8° | 10°°C 0 mm 0% 11 mph 77 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 10 mph 89 % 1029 mb 0 mm/h
Di. März 18 9:00 pm
Wetter-Symbol
4° | 10°°C 0 mm 0% 12 mph 78 % 1027 mb 0 mm/h
Mi. März 19 9:00 pm
Wetter-Symbol
3° | 15°°C 0 mm 0% 7 mph 79 % 1022 mb 0 mm/h
Do. März 20 9:00 pm
Wetter-Symbol
8° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
9° | 10°°C 0 mm 0% 11 mph 52 % 1025 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
8° | 8°°C 0 mm 0% 8 mph 60 % 1025 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 77 % 1027 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 6 mph 84 % 1027 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
4° | 4°°C 0 mm 0% 7 mph 89 % 1027 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
3° | 3°°C 0 mm 0% 7 mph 81 % 1028 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 7 mph 66 % 1029 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
9° | 9°°C 0 mm 0% 8 mph 52 % 1028 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€75,938.30
-1.75%
Ethereum(ETH)
€1,728.68
-2.21%
Fesseln(USDT)
€0.92
-0.01%
XRP(XRP)
€2.12
-5.59%
Solana(SOL)
€118.47
-4.25%
USDC(USDC)
€0.92
0.00%
Dogecoin(DOGE)
€0.154508
-4.13%
Shiba Inu(SHIB)
€0.000012
-0.27%
Pepe(PEPE)
€0.000006
-4.64%
Peanut das Eichhörnchen(PNUT)
€0.189019
20.47%
Nach oben scrollen