ReversingLabs found two malicious NPM packages that used Ethereum smart contracts to conceal downloader URLs and fetch second-stage malware, enabling threat actors to evade security scans by hiding command-and-control links