# Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads

> Quelle: Sonatype — https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads

## Maßnahmen

- [ ] Betroffenheit im eigenen Stack prüfen: Versionen/Komponenten abgleichen.
- [ ] Originalquelle / Hersteller-Advisory lesen: https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads
- [ ] Verfügbaren Patch oder Workaround einspielen und dokumentieren.
