Quasar RAT Hidden in npm Package Targets Ethereum Developers

Amber | Attack Report
Download PDF

A malicious npm package “ethereumvulncontracthandler”, which disguises itself as a tool for detecting Ethereum smart contract vulnerabilities but actually deploys the Quasar Remote Access Trojan (RAT). This malware targets Windows systems, enabling attackers to perform activities like keystroke logging and credential harvesting. To mitigate risks, developers are urged to vet third-party packages and monitor network traffic for unusual activity. The incident emphasizes the need for robust security practices in software supply chains.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox