Six malicious npm packages, including 'js.jadesnow', were discovered using Ethereum blockchain transactions as a command-and-control mechanism to retrieve secondary malicious payloads. The packages embed code that reads data from specific Ethereum wallet transactions, decodes it, and executes the hidden payload. The article does not provide specific affected version ranges, fixed versions, or workarounds for these malicious packages.
2026-08-10 (Back to Inventory) Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads Author(s): Sonatype Research Team Organization: sonatype js.jadesnow Open article directly Related Articles 2026-06-03 â‹… sonatype â‹… Sonatype Security Research Team Lazarus Group's Latest: Brandjacking Campaign on npm 2022-08-11 â‹… sonatype â‹… Ax Sharma PyPI Package 'secretslib' Drops Fileless Linux Malware to Mine Monero 2022-05-20 â‹… sonatype â‹… Ax Sharma New 'pymafka' malicious package drops Cobalt Strike on macOS, Windows, Linux Cobalt Strike