Close Menu
Global News HQ
    What's Hot

    Client Challenge

    July 30, 2025

    Bitcoin Price Calms at $118K Ahead of FOMC Meeting, BONK Dumps Hard: Market Watch

    July 30, 2025

    Luxury Unfiltered: Is your brand still flying?

    July 30, 2025
    Recent Posts
    • Client Challenge
    • Bitcoin Price Calms at $118K Ahead of FOMC Meeting, BONK Dumps Hard: Market Watch
    • Luxury Unfiltered: Is your brand still flying?
    • Strategy Leverages IPO Success to Acquire Over 21,000 Bitcoin
    • Massive quake off Russian coast sparks Pacific-wide tsunami alerts
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • Client Challenge
    • Bitcoin Price Calms at $118K Ahead of FOMC Meeting, BONK Dumps Hard: Market Watch
    • Luxury Unfiltered: Is your brand still flying?
    • Strategy Leverages IPO Success to Acquire Over 21,000 Bitcoin
    • Massive quake off Russian coast sparks Pacific-wide tsunami alerts
    • How to Create an Effective Training Program in 5 Steps
    • Sellers Protest a Major Change to Amazon Feedback Coming August 4th
    • 6 Pilates Exercises for Rheumatoid Arthritis
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Cryptocurrency & Blockchain - North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
    Cryptocurrency & Blockchain

    North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Nemo

    A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

    The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

    The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

    Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

    The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

    The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

    Suspicious code changes

    The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

    The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

    The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

    Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

    The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

    Supply-chain exposure and countermeasures

    The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

    Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

    The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

    Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

    Latest Alpha Market Report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleWhen Is a Car a Character? The Ninth Circuit Revisits Copyrightability in Halicki v. Carroll Shelby Licensing
    Next Article The best Walmart deals to compete with Prime Day: TVs, headphones, laptops, and more

    Related Posts

    Bitcoin Price Calms at $118K Ahead of FOMC Meeting, BONK Dumps Hard: Market Watch

    July 30, 2025

    Strategy Leverages IPO Success to Acquire Over 21,000 Bitcoin

    July 30, 2025

    Strategy Purchases 21,021 Bitcoin After $2.52 Billion IPO

    July 30, 2025

    Billionaire Bill Miller IV says Ethereum and Solana won’t win ‘at the end of the day’

    July 30, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Finance & Investment
    1 Min Read

    Client Challenge

    Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required…

    Bitcoin Price Calms at $118K Ahead of FOMC Meeting, BONK Dumps Hard: Market Watch

    July 30, 2025

    Luxury Unfiltered: Is your brand still flying?

    July 30, 2025

    Strategy Leverages IPO Success to Acquire Over 21,000 Bitcoin

    July 30, 2025
    Top
    Finance & Investment
    1 Min Read

    Client Challenge

    Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required…

    Bitcoin Price Calms at $118K Ahead of FOMC Meeting, BONK Dumps Hard: Market Watch

    July 30, 2025

    Luxury Unfiltered: Is your brand still flying?

    July 30, 2025
    Our Picks
    Finance & Investment
    1 Min Read

    Client Challenge

    Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required…

    Cryptocurrency & Blockchain
    3 Mins Read

    Bitcoin Price Calms at $118K Ahead of FOMC Meeting, BONK Dumps Hard: Market Watch

    Bitcoin’s price actions have calmed in the past several hours around the $118,000 mark, perhaps…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version