BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Target Cryptocurrency Wallets with New Malicious npm Packages

North Korea's Lazarus Group Targets Crypto Wallets with Malicious npm Packages

  • North Korea‘s Lazarus group has been linked to six new malicious npm packages targeting cryptocurrency wallets and sensitive browser data.
  • The attack specifically targets Solana and Exodus crypto wallets by extracting data from popular browsers and macOS keychain.
  • These malicious packages have been downloaded over 330 times, with Socket Security researchers pushing for their removal.

North Korea‘s notorious Hacking collective Lazarus has deployed a fresh attack vector, releasing six malicious npm packages designed to steal cryptocurrency credentials. The Socket Research Team discovered the sophisticated campaign that targets developers while attempting to pilfer data from crypto wallets and browsers.

- Advertisement -

The malicious software specifically extracts sensitive information from Solana and Exodus cryptocurrency wallets by targeting files in Google Chrome, Brave, and Firefox browsers. On macOS systems, the attack additionally targets keychain data, creating a comprehensive theft mechanism aimed at developers who might inadvertently install these packages.

Kirill Boychenko, threat intelligence analyst at Socket Security, explained the attribution challenge in a blog post: “Attributing this attack definitively to Lazarus or a sophisticated copycat remains challenging, as absolute attribution is inherently difficult. However, the tactics, techniques, and procedures (TTPs) observed in this npm attack closely align with Lazarus’s known operations, extensively documented by researchers from Unit42, eSentire, DataDog, Phylum, and others since 2022.”

The six identified packages employ typosquatting techniques, using deceptively misspelled names to trick developers:
– is-buffer-validator
– yoojae-validator
– event-handle-package
– array-empty-validator
– react-event-dependency
– auth-validator

To enhance their deception, the attackers created legitimate-appearing GitHub repositories for five of these packages. “The APT group created and maintained GitHub repositories for five of the malicious packages, lending an appearance of open source legitimacy and increasing the likelihood of the harmful code being integrated into developer workflows,” Boychenko noted.

- Advertisement -

The collective download count for these packages has surpassed 330, with The Socket Team actively working to have them removed after reporting the malicious repositories and associated user accounts.

This latest attack aligns with Lazarus’s extensive history of cryptocurrency-targeted operations. The group has been implicated in several major crypto heists, including the recent $1.4 billion Bybit hack, a $41 million breach of crypto casino Stake, and a $27 million attack on crypto exchange CoinEx.

Lazarus was also initially connected to the $235 million WazirX hack in July 2024, though subsequent investigation by Delhi Police’s Intelligence Fusion and Strategic Operations division led to the arrest of a suspect from Bengal.

Regarding the massive Bybit heist involving approximately $1.4 billion in Ethereum assets, Ben Zhou, Bybit’s CEO, confirmed: “77% are still traceable, 20% have gone dark, 3% have been frozen.”

Security researchers emphasize that these techniques are consistent with previous Lazarus campaigns, with Boychenko stating: “The group’s tactics align with past campaigns leveraging multi-stage payloads to maintain long-term access, the Cybersecurity experts note.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AI Gateway Flaw Exploited, Added to US List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a severe command injection...

Micron Soars on AI Demand, Gets Bullish $1,500 Price Target

Micron stock (MU) surged 170% in 2026 and hit an all-time high of $1,079.57...

Humanity Protocol Hacked: $30M Lost, Token Crashes 85%

Humanity Protocol, a decentralized identity project, lost over $30 million in a private key...

Tokenized Assets Shine Amid 2026 Crypto Slump

The market for tokenized real-world assets grew 589% from early 2025 to June 2026,...

Linux Kernel Flaw Lets Attackers Escalate to Root

A critical Linux kernel vulnerability (CVE-2026-23111) allows local attackers to gain root access and...

Must Read

Buy Domain With Bitcoin: Top 8 Domain Registrars That Accept Bitcoin And Crypto

You are here because you want to buy a domain with bitcoin, right? If you are looking for domain registrars that accept bitcoin or...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading