Ethereum smart contracts are being abused to host payload URLs that download malware via poisoned NPM packages, allowing attackers to fetch second-stage payloads. ReversingLabs found two malicious packages (colortoolsv2, mimelib2)