Skip to main content

Netskope Threat Labs details malicious npm stealer using Bun and Ethereum C2

5 companies named across 4 categories, one of 262 articles referencing Netskope. Previous coverage: Netskope introduces Netskope One DataSec Command Center to manage sensitive data visibility (Aug 2026).

Companies mentioned

Best suited for

Seniority
Director
Job function
Cybersecurity / Information Security
Persona
Security Operations Leader
Buyer role
Decision Maker / Budget Holder
Buyer journey
Need to Buy
Adoption curve
Early Majority
Technology maturity
Market Correction
Industry
Information Technology / Software & Services / IT Services / Cloud Services

Our classification, not the publisher's statement. Best suited for, not only for.

Netskope Threat Labs reports 28 malicious npm versions published on 2026-08-04 across four enterprise namespaces, using a single, shared stealer payload. The report details how the packages run under a signed Bun runtime and exfiltrate credentials and secrets, with a command-and-control endpoint resolved at install time via an Ethereum smart contract.

Research Overview

Netskope Threat Labs analyzed 28 malicious npm package versions published across four unrelated enterprise namespaces: @servicetitan, @or-sdk, @onereach, and @umacloud. The publication activity was recorded from npm registry metadata for 2026-08-04 UTC.

The vendor identifies the campaign operator as Shai-Hulud, referencing consistent naming seen in earlier Netskope reporting. The report states the payload chain was confirmed by detonation in a sandbox environment.

Key Findings

The 28 versions fall into two closely timed publishing bursts, followed by a later release. @or-sdk and @onereach landed at 10:39 UTC, @servicetitan landed at 10:41 UTC, and @umacloud/knowledge arrived at 13:18 UTC.

All versions use an identical or functionally equivalent malicious payload, with a hash match confirmed for @umacloud/[email protected]. The report links the payload to the keyv-family compromise through matching recovered stealer samples, while stating the four namespaces are additional to earlier reporting.

Technical Breakdown

At installation time, the packages fetch a Bun runtime release from GitHub, execute an obfuscated JavaScript stealer under Bun, and delete the runtime afterward. The report states the stealer payload does not include a binary component and does not hardcode a C2 address in the packaged files.

In Netskope’s recovered sample, exfiltration routing is resolved at runtime by calling an Ethereum smart contract using an eth_call. The report states that three public Ethereum RPC providers were tried in sequence until one responded, and it also describes a way to change exfiltration infrastructure by updating contract state rather than republishing packages.

Operational Impact

Netskope’s sandbox detonation against @or-sdk/[email protected] described a credential and secret sweep designed to capture data from both developer systems and CI/CD build targets. The reported targets include SSH private keys, AWS credentials, Docker registry authentication, Jenkins secrets, and /etc/shadow.

The same execution path requests a GitHub CLI token, enumerates AWS Systems Manager Parameter Store and Secrets Manager across 17 regions, and queries EC2 instance metadata via the instance metadata service. The report also describes attempts to authenticate to HashiCorp Vault using the AWS auth method against localhost and exfiltration of an encrypted 4.8 KB bundle to npm-cache.com/router.

The vendor states detection depends on behavioral signals because the tarball does not contain a malicious binary and the executed runtime is legitimately signed. The report’s indicators include the Ethereum contract call selector used for C2 resolution and the exfiltration endpoint used by the campaign.

Blog Signals brief is a fact-based summary of the vendor blog. It covers how a single npm stealer payload, deployed across multiple enterprise namespaces in bursts, runs under a signed Bun runtime and exfiltrates secrets with an install-time C2 resolution mechanism based on Ethereum contract state.

Blog post, originally published by Gianpietro Cutolo at netskope.com.

Structured data (JSON-LD)

The schema.org markup this page publishes for search engines and AI agents, exactly as they read it.

[
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#website",
    "@type": "WebSite",
    "name": "Decision Insights",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://decisioninsights.ai/search/?q={search_term_string}&submit=1"
      }
    },
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    },
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#organization",
    "@type": "Organization",
    "contactPoint": {
      "@type": "ContactPoint",
      "contactType": "customer support",
      "email": "[email protected]"
    },
    "description": "Decision Insights is a Registry of technology companies, open source projects, and industry terms, built for people and for AI agents that need sourced, structured information.",
    "logo": {
      "@type": "ImageObject",
      "url": "https://wiretap-cdn-assets.nyc3.cdn.digitaloceanspaces.com/decision-insights/[email protected]"
    },
    "name": "Decision Insights",
    "parentOrganization": {
      "@type": "Organization",
      "name": "Wiretap Labs",
      "sameAs": [
        "https://www.linkedin.com/company/wiretap-labs",
        "https://www.crunchbase.com/organization/wiretap-labs"
      ],
      "url": "https://wiretaplabs.com"
    },
    "publishingPrinciples": "https://decisioninsights.ai/standards/",
    "sameAs": [
      "https://www.linkedin.com/company/decisioninsights"
    ],
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "itemListElement": [
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai",
        "name": "Decision Insights",
        "position": 1
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/records/",
        "name": "Records",
        "position": 2
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/netskope-threat-labs-details-malicious-npm-stealer-using-bun-and-ethereum-c2/",
        "name": "Netskope Threat Labs details malicious npm stealer using Bun and Ethereum C2",
        "position": 3
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/netskope-threat-labs-details-malicious-npm-stealer-using-bun-and-ethereum-c2/#blogposting",
    "@type": "BlogPosting",
    "about": {
      "@id": "https://decisioninsights.ai/registry/netskope/#organization",
      "@type": "Organization",
      "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
      "name": "Netskope"
    },
    "audience": [
      {
        "@type": "Audience",
        "additionalType": "Seniority",
        "audienceType": "Director"
      },
      {
        "@type": "Audience",
        "additionalType": "Job function",
        "audienceType": "Cybersecurity / Information Security"
      },
      {
        "@type": "Audience",
        "additionalType": "Persona",
        "audienceType": "Security Operations Leader"
      },
      {
        "@type": "Audience",
        "additionalType": "Buyer role",
        "audienceType": "Decision Maker / Budget Holder"
      },
      {
        "@type": "Audience",
        "additionalType": "Adoption curve",
        "audienceType": "Early Majority"
      },
      {
        "@type": "Audience",
        "additionalType": "Technology maturity",
        "audienceType": "Market Correction"
      },
      {
        "@type": "Audience",
        "additionalType": "Industry",
        "audienceType": "Information Technology / Software & Services / IT Services / Cloud Services"
      }
    ],
    "author": {
      "@id": "https://decisioninsights.ai/author/decision-insights-coverage/#person",
      "@type": "Person",
      "name": "Decision Insights Coverage",
      "url": "https://decisioninsights.ai/author/decision-insights-coverage/"
    },
    "dateModified": "2026-08-23T12:45:43-06:00",
    "datePublished": "2026-08-04T15:43:29-06:00",
    "description": "Netskope Threat Labs reports 28 malicious npm package versions across four namespaces, with a stealer run under Bun and C2 resolved via Ethereum contract.",
    "headline": "Netskope Threat Labs details malicious npm stealer using Bun and Ethereum C2",
    "isBasedOn": {
      "@type": "CreativeWork",
      "author": {
        "@type": "Person",
        "name": "Gianpietro Cutolo"
      },
      "sourceOrganization": {
        "@id": "https://decisioninsights.ai/registry/netskope/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
        "name": "Netskope"
      },
      "url": "https://www.netskope.com/blog/npm-stealer-reads-its-c2-from-an-ethereum-contract"
    },
    "keywords": [
      "Enterprise",
      "Ethereum",
      "Metadata",
      "Threats"
    ],
    "mainEntityOfPage": {
      "@id": "https://decisioninsights.ai/netskope-threat-labs-details-malicious-npm-stealer-using-bun-and-ethereum-c2/",
      "@type": "WebPage",
      "sdDatePublished": "2026-08-23",
      "sdPublisher": {
        "@id": "https://decisioninsights.ai/#organization"
      }
    },
    "mentions": [
      {
        "@id": "https://decisioninsights.ai/registry/amazon.com/amazon-web-services-aws/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/amazon.com/amazon-web-services-aws/",
        "name": "Amazon Web Services (AWS)"
      },
      {
        "@id": "https://decisioninsights.ai/registry/docker-inc/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/docker-inc/",
        "name": "Docker"
      },
      {
        "@id": "https://decisioninsights.ai/registry/microsoft/github/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/microsoft/github/",
        "name": "GitHub"
      },
      {
        "@id": "https://decisioninsights.ai/registry/hashicorp/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/hashicorp/",
        "name": "HashiCorp"
      },
      {
        "@id": "https://decisioninsights.ai/registry/netskope/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/netskope/",
        "name": "Netskope"
      },
      {
        "@id": "https://decisioninsights.ai/projects/bun/#project",
        "@type": "SoftwareSourceCode",
        "mainEntityOfPage": "https://decisioninsights.ai/projects/bun/",
        "name": "Bun"
      },
      {
        "@id": "https://decisioninsights.ai/projects/docker/#project",
        "@type": "SoftwareSourceCode",
        "mainEntityOfPage": "https://decisioninsights.ai/projects/docker/",
        "name": "Docker"
      },
      {
        "@id": "https://decisioninsights.ai/projects/jenkins/#project",
        "@type": "SoftwareSourceCode",
        "mainEntityOfPage": "https://decisioninsights.ai/projects/jenkins/",
        "name": "Jenkins"
      }
    ],
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    }
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/author/decision-insights-coverage/#person",
    "@type": "Person",
    "description": "Blog posts, podcasts, and video analysis from across the industry, condensed into short, sourced summaries. Produced under our Standards & Methodology.",
    "name": "Decision Insights Coverage",
    "sameAs": [
      "https://www.linkedin.com/showcase/decisioninsights/"
    ],
    "url": "https://decisioninsights.ai/author/decision-insights-coverage/"
  }
]

Is this your company? Get structured data for your own pages