THREAT OPS › Threat News › Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
<div class="hs-featured-image-wrapper"> <a class="hs-featured-image-link" href="https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads" title=""> <img alt="Image with text: "Breaking news, Sonatype Research identified sonatype-2026-005899, DPRK 'Contagious Interview'"" class="hs-featured-image" src="https://www.sonatype.com/hubfs/RapidRe
Attributed threat actors
- Contagious InterviewG1052
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- e059ff2a8ab914cb2d79bf48cb86863emd5
- c89e5f7cdda40da39c08dc60049b9ac9md5
- https://guide.sonatype.com/vulnerability/sonatype-2026-005899url
- https://guide.sonatype.com/vulnerability/sonatype-2026-005901url
- https://opensourcemalware.com/blog/nullreceiver-dprk-c2-techniqueurl
- track.hubspot.comdomain
- 2fwww.sonatype.comdomain
- 252fwww.sonatype.comdomain