Wednesday, July 23, 2025
  • Login
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
CRYPTO MARKETCAP
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS
No Result
View All Result
SB Crypto Guru News- latest crypto news, NFTs, DEFI, Web3, Metaverse
No Result
View All Result

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

by SB Crypto Guru News
June 19, 2025
in Crypto Exchanges
Reading Time: 3 mins read
0 0
A A
0


NemoNemo

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

Latest Alpha Market Report



Source link

Tags: Bitcoin NewsCodecredentialstealingCrypto NewsCrypto UpdatesDevDormanthijacksKoreanLatest News on CryptoNorthrepositoriesSB Crypto Guru NewsSlipsUpdatesWalletWAVES
Previous Post

Checkpoint #4: Berlinterop | Ethereum Foundation Blog

Next Post

Coinbase Delivers USDC Breakthrough in US Futures Trading

Related Posts

SEC approved Bitwise ETF, then paused it

SEC approved Bitwise ETF, then paused it

by SB Crypto Guru News
July 23, 2025
0

The US Securities and Exchange Commission (SEC) has issued a stay order on Bitwise’s bid to convert its over-the-counter (OTC)...

Ark Invest pivots to BitMine amid rising Ethereum treasury

Ark Invest pivots to BitMine amid rising Ethereum treasury

by SB Crypto Guru News
July 22, 2025
0

Cathie Wood’s Ark Invest has shifted its crypto-focused investment strategy, reducing its holdings in Coinbase, Robinhood, and Block in favor of BitMine...

Mag 7 Leaders and Laggards

Mag 7 Leaders and Laggards

by SB Crypto Guru News
July 22, 2025
0

The Daily Breakdown takes a closer look at the Magnificent 7 to gauge which stocks have been leaders and which...

Bitcoin price to hit 7,000 by next cycle from combined institutional predictions

Bitcoin price to hit $917,000 by next cycle from combined institutional predictions

by SB Crypto Guru News
July 21, 2025
0

Following a new all-time high in dollars, Bitcoin price predictions are flooding in alongside diverging institutional theses, ranging from macro-driven...

The Daily Breakdown: 3 Things to Watch: Crypto, GOOGL, TSLA

The Daily Breakdown: 3 Things to Watch: Crypto, GOOGL, TSLA

by SB Crypto Guru News
July 21, 2025
0

It’s a big week of earnings, headlined by Alphabet and Tesla. The Daily Breakdown dives into this week’s big events....

Load More
Next Post
Coinbase Delivers USDC Breakthrough in US Futures Trading

Coinbase Delivers USDC Breakthrough in US Futures Trading

Dogecoin (DOGE) Struggles to Climb — Upside Moves Likely to Face Strong Resistance

Dogecoin (DOGE) Struggles to Climb — Upside Moves Likely to Face Strong Resistance

Facebook Twitter LinkedIn Tumblr RSS

CATEGORIES

  • Altcoin
  • Analysis
  • Bitcoin
  • Blockchain
  • Crypto Exchanges
  • Crypto Updates
  • DeFi
  • Ethereum
  • Metaverse
  • Mining
  • NFT
  • Regulations
  • Scam Alert
  • Uncategorized
  • Web3

SITE MAP

  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • HOME
  • BITCOIN
  • CRYPTO UPDATES
    • GENERAL
    • ALTCOINS
    • ETHEREUM
    • CRYPTO EXCHANGES
    • CRYPTO MINING
  • BLOCKCHAIN
  • NFT
  • DEFI
  • WEB3
  • METAVERSE
  • REGULATIONS
  • SCAM ALERT
  • ANALYSIS

Copyright © 2022 - SB Crypto Guru News.
SB Crypto Guru News is not responsible for the content of external sites.