# Malicious npm Packages Hide C2 IPs in Ethereum Addresses

Researchers found trojanized npm packages that conceal command-and-control server IPs within Ethereum recipient addresses to bypass detection. The packages target software developers, posing a supply-chain risk. Developers are advised to audit dependencies and registry sources.

**Importance:** 3/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/08/trojanized-npm-packages-decode-c2-ip.html) — Wed, 05 Aug 2026 19:11:27 +0530
- [The Hacker News](https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html) — Sat, 08 Aug 2026 00:18:17 +0530