Breaking
February 14, 2025

N.Korean Hackers Boost Crypto-Looting Methods: Hiding Malware in GitHub, NPM Packages Sead Fadilpašić | usagoldmines.com

For months now, North Korea has been targeting crypto developers via NPM supply chain attacks. This is a highly sophisticated global campaign orchestrated by the infamous Lazarus group to steal funds and data through supply chain attacks.

Starting in August 2024, the group has been inserting malicious JavaScript into GitHub repositories and NPM packages. This operation is named Marstech Mayhem, and the malware’s assigned title is Marstech1, Computing reported.

What’s more, Marstech1 targets popular cryptocurrency wallets. Various reports have named MetaMask, Exodus, and Atomic.

The malicious code enters the system undetected, scans for the wallets across Windows, macOS, and Linux, seizes control of browser configuration files, and starts intercepting transactions and extracting metadata.

This approach increases the risk of the malicious code spreading, therefore raising the threat to the global software supply chain significantly. Others may unknowingly download the compromised software packages, introduce them into different applications, and expose countless other users to danger.

Global Operation from North Korea Targeting Crypto Devs

The group presumed to be Lazarus hides the malicious JavaScript implant in GitHub repositories and NPM packages – which are typically used by crypto devs and Web3 developers, according to a report by The Registar.

NPM is the default package manager for the Node.js platform. It is used to install, publish, and manage Node.js packages. In fact, according to Contrast Security, NPM “is the single largest language code repository globally.”

A report by cybersecurity company SecurityScorecard stated on 30 January that Lazarus has been altering legitimate software packages by embedding obscured backdoors and then tricking developers into executing these compromised packages.

“To the untrained eye it goes unnoticed by the victim and successfully executes. These packages may involve anything from cryptocurrency applications to authentication solutions,” the report said.

Source: SecurityScorecard

SecurityScorecard found 233 confirmed individual victims who have installed the new Marstech1 implant between September 2024 and January 2025. Many features of this code “demonstrate North Korea’s evolving tradecraft,” it said.

What’s more, the implant now comes with multiple obfuscation layers, showcasing a constant effort to advance the technique and stay ahead of detection measures.

Therefore, the crypto/Web3 devs’ dependence on NPM combined with Marstech1’s ability to conceal itself pose a massive danger to the space.

“This analysis makes it evident that Lazarus was orchestrating a global operation targeting the cryptocurrency industry and developers worldwide,” the report reads. “The campaigns resulted in hundreds of victims downloading and executing the payloads, while, in the background, the exfiltrated data was being siphoned back to Pyongyang.”

The post N.Korean Hackers Boost Crypto-Looting Methods: Hiding Malware in GitHub, NPM Packages appeared first on Cryptonews.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Crypto News | US customs reportedly stalling Bitcoin miner shipments amid crackdown Gino Matos | usa...

Crypto News | Trump reportedly considering swapping crypto council for informal summits Gino Matos |...

Crypto News | FBI initiative saves thousands from crypto scams, recovers $285 million Assad Jafri | ...

Crypto News | Robinhood CEO says ‘innovation-friendly’ US crypto policies a ‘tailwind’ for firm’s fu...

NFT brand Doodles plans to launch Solana-based token $DOOD Brenda Kanana | usagoldmines.com

Mastercard says 30% of its transactions in 2024 were tokenized Cryptopolitan News | usagoldmines.com

Former SEC official declares crypto enforcement ‘dead and buried’ Brenda Kanana | usagoldmines.com

Crypto Bulls Are Turning to This Altcoin at $0.01 After the Ripple (XRP) Party Ended Early Cryptopol...

Avalanche Shows Signs Of Recovery As Key Indicator Flashes A Buy Signal – Details Sebastian Villafue...

U.S. States Push for Bitcoin Reserves Could Trigger $23 Billion in Purchases: Matthew Sigel Nidhi Ko...

JPMorgan Warns Tether May Sell Bitcoin Amid US Stablecoin Regulations Mustafa Mulla | usagoldmines.c...

Bitcoin on the Edge? Analysts Warn of a Major Crash Ahead Nidhi Kolhapur | usagoldmines.com

US PPI Exceeds Wall Street Estimates; Bitcoin Surges Past $96K Nidhi Kolhapur | usagoldmines.com

Russian Brokerage Finam to Offer Notes Linked to BlackRock’s Bitcoin ETF Nidhi Kolhapur | usagoldmin...

Cardano Whales Scoop Up 70 Milion ADA, $1.13 Next? Chandan Gupta | usagoldmines.com

Whale Buy $341 Million Worth TRUMP Meme Coin, Rally Imminent? Chandan Gupta | usagoldmines.com

Plasma’s New Tether Blockchain Promises Zero-Fee Transactions, Launch Expected This Year Nidhi Kolha...

Ethereum Whale Sell-off 20,000 ETH, Traders’ Eyes on $2,200 Chandan Gupta | usagoldmines.com

XRP Price Prediction for February 14 Chandan Gupta | usagoldmines.com

Whales accumulate $3.8B in Bitcoin during the recent dip, with a net inflow of 40K BTC on Feb 5 Coll...

Ethereum Foundation Allocates $120 Million of ETH to DeFi Protocols Jimmy Aki | usagoldmines.com

Crypto Exchange Bitget Secures VASP License in Bulgaria Tanzeel Akhtar | usagoldmines.com

Bitcoin Wallets Decline as Small Traders Exit, Signaling Potential Whale Accumulation Veronika Rinec...

JPMorgan Quietly Gains Bitcoin Exposure – Could This Signal a Major Institutional Shift? Arslan Butt...

Bitcoin Flag Pole Pattern Puts Price At $120,000, Analyst Explains The Roadmap Scott Matherson | usa...

Dubai virtual assets regulator warns against investing in memecoins Lara Abdul Malak | usagoldmines....

The Best DeFi Lending Altcoin Priced Below $0.10 for Long-Term Growth Cryptopolitan Media | usagoldm...

Musk says Grok 3 is in the final development stages, to be released in coming weeks Shummas Humayun ...

Pro-crypto Robert F. Kennedy Jr. confirmed as US Secretary of Health Jai Hamid | usagoldmines.com

Pumpfun deposited 148,759 SOL ($28.22M) to Kraken again, earning a cumulative total of $540.5M Colli...

Institutional Money Flows Into Solana – Could Franklin Templeton’s Move Push SOL to $10,000?  Harvey...

Why Decentralized Data Is Needed As AI Matures Rachel Wolfson | usagoldmines.com

Customs Hold Bitmain Equipment, Disrupting U.S. Bitcoin Mining Supply Chains Hongji Feng | usagoldmi...

CZ Sparks Memecoin Frenzy With Dog Picture: Four.Meme Starts Token Betting Event Rubmar Garcia | usa...

Cardano Price Balloons 107% As Whales Scoop Up 1.41 Billion ADA Christian Encila | usagoldmines.com

Bankr Bot: Trading Crypto Is as Easy as Sending a Message Victor | usagoldmines.com

Sumer Money Hits $100M TVL Ahead of Berachain Launch Victor | usagoldmines.com

BNB Chain Announces Major Upgrades for 2025 Tari | usagoldmines.com

Coinbase Adds POPCAT and PENGU on Solana Victor | usagoldmines.com

New York’s Bitcoin Bill Aims to Study Crypto’s Effects Victor | usagoldmines.com

Former Google CEO Eric Schmidt says ‘rogue states or terrorists’ can misuse AI to harm innocent peop...

Chainalysis: 2024 was a record year for scammers, with more sophisticated tactics Hristina Vasileva ...

Borderlands 4 to release in September 2025 – Where does that leave GTA 6? Noor Bazmi | usagoldmines....

How Ripple’s RLUSD Stablecoin Could Drive Crazy Demand For XRP Amid Push Into $230 Billion Payments ...

Mutuum Finance: This Altcoin is Set for 10,000% Gains in Just 6 Months—Why You Should Pay Attention ...

Shiba Inu (SHIB) Records Outflows as Investor Confidence Shifts to $0.006 Token Tipped to Rise 15554...

Cardano Echoes 2020-2021 Pattern – Is A Parabolic Rally On The Horizon? Sebastian Villafuerte | usag...

Metaplanet completes raise of 4.0 Billion JPY in Ordinary Bonds to purchase Bitcoin Collins J. Okot...

The Ethereum Foundation supplies 10K ETH to Spark and Aave, doubling down on DeFi Collins J. Okoth |...

Global economic consequences of the Ukraine-Russia peace Florence Muchai | usagoldmines.com

A bearish trade is looming for US equities, Goldman Sachs says Florence Muchai | usagoldmines.com

Robinhood is using stablecoins to power its weekend settlements Cryptopolitan News | usagoldmines.co...

Thanks to Trump, Corporate America can’t avoid Bitcoin now Jai Hamid | usagoldmines.com

US crypto miners struggle with equipment delays because of Trump Jai Hamid | usagoldmines.com

Search engine queries on ‘criminal defense attorney’ peak in DC in response to Elon’s DOGE rampage F...

Senate Democrats accuse Treasury Secretary Bessent of deception with D.O.G.E Jai Hamid | usagoldmine...

Plasma raises $24M to launch zero-fee blockchain for Tether in Q2 Jai Hamid | usagoldmines.com

Cathie Wood Doubles Down On $1.5 Million Bitcoin Price By 2030, Market Reacts Aliyu Pokima | usagold...

Tether CEO Paolo Ardoino Dismisses JP Morgan’s Bitcoin Sell-Off Prediction Hassan Shittu | usagoldmi...

Shiba Inu Price Chart Flashes a Massive Buy Signal – $1 SHIB Incoming? Alejandro Arrieche | usagoldm...

TRUMP Coin Crashes 80% – But a Bullish Pattern Could Send It Surging Soon  Harvey Hunter | usagoldmi...

PEPE Holders Get Ready – Bullish Reversal Pattern Hints at a Big Price Surge Alejandro Arrieche | us...

OpenSea Confirms SEA Token Airdrop, Launches OS2 Open Beta Version Tanzeel Akhtar | usagoldmines.com

Could This Be the Next XRP? OFFICIAL MAGACOIN Is Gaining Massive Attention! Cryptopolitan Media | us...

Ancient Bitcoin Whales Transfer 14K BTC After Seven Years, What’s Going On? Aliyu Pokima | usagoldmi...

Pundit Sounds Major Crash Alarm For XRP Price As ’12-Year Cycle’ Comes To An End Scott Matherson | u...

Bybit CEO Rejects Pi Token Listing Amid Pyramid Scheme Controversy Hassan Shittu | usagoldmines.com

Silicon Valley jumps into Trump’s second term: Tech surrounds Washington Florence Muchai | usagoldmi...

Astra Nova and Shiba Inu Forge Alliance to Elevate AI in Entertainment Cryptopolitan Media | usagold...

JPMorgan says Tether may need to sell Bitcoin to comply with US stablecoin regulations Florence Much...

Vitalik Buterin pitches Railgun model as privacy and fraud pre-screening solution Hristina Vasileva ...

Can Mutuum Finance (MUTM) Disrupt DeFi? Investors Who Made Millions During the 2020 DeFi Summer are ...

Bitcoin Dips Below $95K as January CPI Data Shows Increasing Inflation. Can $MEMEX 100x? Krishi Chow...

BNB Uptrend Gears Up: 10% Jump Brings $724 Resistance Into Play Godspower Owie | usagoldmines.com

Mastercard tokenized 30% of its 2024 transactions per SEC filing Oluwapelumi Adejumo | usagoldmines....

OpenSea announces upcoming SEA token amid OS2 open beta launch Liam 'Akiba' Wright | usagoldmines.co...

Tether refutes JPMorgan’s suggestion it will sell Bitcoin to navigate regulation Oluwapelumi Adejumo...

Web3 Alliance of Saudi Arabia (WASA) launches with Sandbox, Animoca Brands and Outlier Ventures on b...

Sony bets high on gaming profits as PS5 sales exceed expectations Noor Bazmi | usagoldmines.com

Elon Musk’s D.O.G.E to shut down NASA Jai Hamid | usagoldmines.com

Mass Bitcoin sell-off? Why this could actually be bullish Ashish Kumar | usagoldmines.com

CZ Hints at Meme Coin Based on His Dog, Teases BNB Chain Involvement Hassan Shittu | usagoldmines.co...

Deutsche Bank-Backed Taurus Integrates with Solana, Enables Institutions to Enter Tokenized Asset Sp...

Crypto Scammers Use AI and Professional Networks to Rake in Billions – Chainalysis Report Veronika R...

US Regulators Explore New Ways to Jointly Work on Crypto Regulations: Report Jimmy Aki | usagoldmine...

Top Meme Coins to Invest In As Binance’s CZ Contemplates New Pet Coin Krishi Chowdhary | usagoldmine...

4 Best Altcoins to Invest in as Ripple Partners with 10 Central Banks NewsBTC | usagoldmines.com

Bitcoin To $1.5 Million? Ark Invest CEO Cathie Wood Says It’s Coming Christian Encila | usagoldmines...

Rising CPI data triggered specific selling among US traders Andjela Radmilac | usagoldmines.com

Crypto News | Cboe seeks SEC approval for staking in 21Shares Ethereum ETF Oluwapelumi Adejumo | usa...

Crypto News | Metaplanet fuels Bitcoin ambitions with $26 million raise as it enters MSCI Japan Inde...

Crypto News | Pi Network prepares to open to external networks amid listing challenges Oluwapelumi A...

Crypto News | Ethereum Foundation on-course to earn $1.5 million through allocation of 50k ETH to De...

Crypto News | SEC and CFTC seek united front on digital asset regulation with revival of advisory co...

Bitcoin Mining Explosion in Malaysia Exposes Power Theft Activities, Authorities Step In Anjali Bel...

DePAI Explained: Transforming AI and Robotics with DePIN Tari | usagoldmines.com

The time of ‘white flag’ GOP is over as DOGE targets wasteful spending – Investors take Florence Muc...

South Korea to allow charities, universities, and crypto exchanges to sell digital assets Nellius Ir...

Mutuum Finance (MUTM) Token Gets Ready To Challenge Solana (SOL) and Ripple (XRP) Dominance in Crypt...

NVIDIA Inception Welcomes Astra Nova to Pioneer AI-Driven Entertainment Cryptopolitan Media | usagol...

Leave a Reply