A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise.
The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
A Bluesky post by lazarusholic shared a Sonatype report titled "Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads." The post said the campaign involved six npm packages using Ethereum transactions to retrieve malicious payloads and referenced ContagiousInterview and NullReceiver.
Splunk Threat Research removed the detection "Cmdline Tool Not Executed In CMD Shell" from its content library in version 5.2.0, stating it had been renamed and its logic updated. Splunk identified the replacement as "Windows Cmdline Tool Execution From Non-Shell Process."
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.