Malicious npm Package Modifies Local ‘ethers’ Library to Launch Reverse Shell Attacks

Two malicious packages that are intended to infect another locally installed package have been found by cybersecurity experts on the npm registry, highlighting the ongoing development of software supply chain hacks that target the open-source community.

Since its publication on March 15, 2025, the packages in question—ethers-provider2 and ethers-providerz—have been downloaded 73 times. No one downloaded the second package, which was probably deleted by the virus creator.

In a study provided with The Hacker News, Lucija Valentić, a researcher from ReversingLabs, claimed that they were straightforward downloaders with a carefully concealed harmful payload.

Their second stage, which would ‘patch’ the locally installed legitimate npm package ethers with a new file holding the malicious payload read more about Malicious npm Package Modifies Local ‘ethers’ Library to Launch Reverse Shell Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *