GoCaracal: C2 via Ethereum smart contract extends beyond npm - blockchain technology becomes standard

In this saga : Attaques supply chain npm : paquets malveillants et techniques d'évasion· Episode 2/2

Cybersecurity Aug 28, 2026Add to bookmarks

GoCaracal: C2 via Ethereum smart contract extends beyond npm - blockchain technology becomes standard

GoCaracal, a new RAT malware, stores its command-and-control addresses in an Ethereum smart contract. Following the 7 fake Vite npm packages from August 2026, the blockchain C2 technique confirms its scaling across multiple malware families.

What: GoCaracal, New RAT, Drives Its C2 via the Ethereum Blockchain

GoCaracal is a Remote Access Trojan (RAT) — a remote access Trojan — recently documented by security researchers. Its technical peculiarity: it stores its command-and-control (C2) addresses not in a configuration file or a classic DNS domain, but in an Ethereum smart contract. When defenders seize or block a C2 server, the malware operator simply updates the address in the Ethereum contract — and all infected agents automatically switch to the new C2, without any malware update.

This is not a completely new technique, but its growing adoption is a strong signal: after the 7 fake Vite npm packages documented in late August 2026 (which already used an Ethereum smart contract as C2), GoCaracal confirms that the technique is spreading beyond the npm ecosystem alone.

Why It's Hard to Counter

Traditional defense mechanisms against C2 rely on DNS blocking, domain seizure, or IP null-routing. None of these methods work against a C2 stored on the Ethereum blockchain:

  • Partial immutability: the smart contract itself is immutable once deployed, but the C2 address it stores can be updated by the operator (via a write function of the contract).
  • Seizure resistance: there is no blockchain equivalent of “domain takedown” — no registrar, no host, no authority to contact.
  • Discretion: querying an Ethereum smart contract resembles ordinary HTTPS traffic to public RPC nodes (Infura, Alchemy) — difficult to distinguish from legitimate web traffic.

Evolution of the npm Supply Chain Attack Chain

GoCaracal represents a significant shift: the blockchain C2 technique is no longer confined to npm supply chain attacks. It is expanding to broader malware distribution. What was once a tactical curiosity in the Vite npm incident has become a generic pattern that blue teams must integrate into their detection models.

The initial distribution vector of GoCaracal remains to be clarified in ongoing analyses, but its C2 mechanism applies to any malware, regardless of the initial infection method.

What to Do Now

What to do now:

  1. Monitor outgoing Ethereum RPC requests in your proxies and NGFW — nodes like Infura (mainnet.infura.io), Alchemy, and Cloudflare Ethereum (cloudflare-eth.com) are standard access points.
  2. Alert on eth_call requests to unknown smart contracts from internal endpoints.
  3. Block public Ethereum RPC nodes if no legitimate use case exists in your organization (unlikely for most companies).
  4. Integrate the published GoCaracal IoCs into your EDR/SIEM solutions.
Blockchain C2: The Technique That Resists Seizure

A classic C2 domain can be seized within hours via registrars. An Ethereum smart contract cannot be 'seized': there is no registrar or host to contact. Only the contract operator can modify its content — and they can do so from anywhere in the world.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

18 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
The saga

Attaques supply chain npm : paquets malveillants et techniques d'évasion

  1. 1npm Vite: 7 malicious plugins deliver RAT via blockchain C2—a C2 technique resistant to takedowns27/08/2026
  2. 2GoCaracal: C2 via Ethereum smart contract extends beyond npm - blockchain technology becomes standard28/08/2026
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information