GoCaracal: C2 via Ethereum smart contract extends beyond npm - blockchain technology becomes standard
GoCaracal, a new RAT malware, stores its command-and-control addresses in an Ethereum smart contract. Following the 7 fake Vite npm packages from August 2026, the blockchain C2 technique confirms its scaling across multiple malware families.
Aug 28, 2026 18 3








