Lazarus Group Hack Crypto Developers, Creating Backdoors in NPM Repositories

Lazarus Group Hack Crypto Developers, Creating Backdoors in NPM Repositories
фото показано с : zycrypto.com

2025-3-14 03:29

Lazarus Group, hackers from North Korea, created a new campaign, targeting crypto developers through NPM repositories. They introduced 6 repositories, that would appeal to crypto developers, and added malware, to create backdoors, infiltrate projects, and steal credentials. 

The hacking group would use BeaverTail, a malware package, to execute a hidden file on the target system. The malware would then steal credentials by accessing browser files and searching for files related to cryptocurrency wallets like Exodus. The stolen data would then be sent to a command and control centre so that the hackers could readily access the sensitive files.

“Attributing this attack”, wrote Kirill Boychenko, Socket Seniority Analyst, “definitively to Lazarus or a sophisticated copycat remains challenging, as absolute attribution is inherently difficult. However, the tactics, techniques, and procedures (TTPs) observed in this npm attack closely align with Lazarus’s known operations, extensively documented by researchers from Unit42, eSentire, DataDog, Phylum, and others since 2022”.

The NPM repositories were based on actual libraries, but used typosquatting and similar spelling to mimic popular packages and trick developers into installing them. The malicious packages were downloaded over 300 times, showing the reach of the attack. 

The six malicious packages include: 

is-buffer-validator – mimics is-buffer library, steals credentials.  yoojae-validator – fake validator, steals sensitive data.  event-handle-package – pretends to be an event handling tool, but installs a back door for remote access.  array-empty-validator – collects browser and system credentials.  react-event-dependency – pretends to be a react utility, but compromises developer environments.  auth-validator – steals login and API credentials. 

“The APT group”, wrote Boychenko, “created and maintained GitHub repositories for five of the malicious packages, lending an appearance of open source legitimacy and increasing the likelihood of the harmful code being integrated into developer workflows”.

The malware was designed to collect system information, such as operating system, system directories, and hostname, deploying this attack to hundreds of NPM users. 

“It systematically iterates through browser profiles”, wrote Boychenko, “to locate and extract sensitive files such as Login Data from Chrome, Brave, and Firefox, as well as keychain archives on macOS. Notably, the malware also targets cryptocurrency wallets, specifically extracting id.json from Solana and exodus.wallet from Exodus”.

This attack is part of Lazarus Group’s broader strategy to disrupt supply chains. The NPM malware allows them to target developers, a vital part of the global supply chain, and embed themselves inside systems, development environments, and crypto addresses to further their attacks. Similar methods have been used to target GitHub and Python’s pip packages. 

“Continuous monitoring of unusual dependency changes”, wrote Boychenko, “can expose malicious updates while blocking outbound connections to known C2 endpoints prevents data exfiltration. Sandboxing untrusted code in controlled environments and deploying endpoint protection can detect suspicious file system or network activities”. 

Boychenko raises a critical point because developers, due to tight deadlines, often use many libraries without fully checking them. Cryptocurrency, being decentralized, allows developers to collaborate over vast distances, but also increases the attack vector of open source projects.

According to the United Nations 2024 report, North Korean hackers were responsible for 35% of cryptocurrency thefts, amounting to $1 billion in lost crypto. The hackers pose a new kind of security threat, being state actors, because they may use their accumulated wealth to fund nuclear weapons programs and ballistic missile enhancements.

origin »

Emerald Crypto (EMD) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 4.67 %
Cегодня L: $0 - H: $0
Капитализация $0 Rank 99999
Доступно / Всего 19.117m EMD / 32m EMD

developers crypto repositories npm backdoors group lazarus

developers crypto → Результатов: 126


New Crypto Developers Growing for the First Time since 2017: Electric Capital Report

Just as the price of Bitcoin and digital assets start surging, so does the talent which has been flocking back to the cryptocurrency market in the last few months. Software developers are making their back into the world of crypto at a level that hasn’t been seen since the market peaked three years ago when […] The post New Crypto Developers Growing for the First Time since 2017: Electric Capital Report first appeared on BitcoinExchangeGuide.

2020-12-11 17:23


Фото:

Op Ed: Defining Decentralization: How Ambiguity Continues to Divide Crypto

There are many keywords in blockchain, but few spark as much emotion as “decentralization. ” For many of us, it was the dream of decentralization that inspired us to embark into the industry in the first place — the driving force encouraging us to explore the many industries and practice areas that could be positively impacted by this technology.

2019-3-1 19:43


NeuralTrade Network ICO

Most people are desperately seeking financial freedom in their life. Sadly financial freedom remains a dream to them or an elusive theory that forever escapes them. The biggest problem around financial freedom is some magic formula or some secret success model that they believe exists, they spend an endless amount of time, effort and even resources in obtaining this magic formula or the secret success model.

2019-2-15 22:51


NUPay ICO

In the belief that cryptocurrencies will soon become the norm as a payment tool or “money,” numerous startups and companies are preparing to launch cryptocurrency-related services and technologies. TPCT, NUPay’s brand token, functions as a medium of exchange and a store of value that can be spent and collected, credited, or accumulated through the NUPay Payment System.

2019-2-13 09:33


Фото:

Sapphire Introduces New GPU Designed to Mine Grincoin

Grincoin seems to be on the right track towards being one of the most important cryptocurrencies on the global market cap. Its technology and the enthusiasm of the community has led developers and hardware manufacturers to put their eyes on this young crypto and Sapphire is an example of this, recently announcing the release of […] The post Sapphire Introduces New GPU Designed to Mine Grincoin appeared first on Ethereum World News.

2019-1-25 06:16


Фото:

Lisk Devs Refuse To Paint Rosy Picture: We Have Learned The Hard Way

As the saying goes, if you build it, they will come. Blockchain application platform Lisk hasn’t built its key tool yet. Nonetheless, the community has shown up. Lisk is building a Sidechain Development Kit (SDK), which will make it easy for JavaScript developers to “deploy their own sidechain and develop blockchain applications on top of […] The post Lisk Devs Refuse To Paint Rosy Picture: We Have Learned The Hard Way appeared first on Crypto Briefing.

2019-1-23 23:21


Crypto Pundits Skeptical Of “Better Bitcoin” Plan From MIT, Stanford

Since Bitcoin began to pick up steam in 2016, the network, coupled with its core developers, has been criticized by cynics en-masse for its inability to scale. And while evident strides are being made, with solutions like the Lightning Network and Segregated Witness seeing rapid adoption, innovators have still sought to one-up the world’s first.

2019-1-18 16:06


3rd Global forum “Blockchain Life” comes to Singapore

On April 23-24 the global blockchain and cryptocurrency industry meets at Blockchain Life 2019 Asia in Singapore. | 5000+ attendees | 80+ speakers | 70+ countries | 120+ booths Top managers of international blockchain companies, crypto traders and analysts, funds and investors, perspective ICO and STO projects, developers and miners will meet again to discuss […] The post 3rd Global forum “Blockchain Life” comes to Singapore appeared first on NullTX.

2019-1-18 01:01