Advertising
News4Social English
  • News
    • National
    • Education
    • Review
    • Space
    • Environment
  • Health Trends
  • Business
  • Lifestyle
  • Travel
  • Cryptocurrency
  • Sports
  • World
No Result
View All Result
  • News
    • National
    • Education
    • Review
    • Space
    • Environment
  • Health Trends
  • Business
  • Lifestyle
  • Travel
  • Cryptocurrency
  • Sports
  • World
No Result
View All Result
News4Social English
No Result
View All Result
Advertising
Home Cryptocurrency

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

June 19, 2025
in Cryptocurrency
Reading Time: 2 mins read
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
295
SHARES
1.4k
VIEWS
Share on TwitterShare on Telegram
Advertising

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

Advertising

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

Advertising

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

Advertising

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

RelatedPosts

Bitcoin Bears Strike Back After ATH: Long/Short Ratio Flips Negative

Bitcoin Bears Strike Back After ATH: Long/Short Ratio Flips Negative

July 15, 2025
Ripple expands RLUSD globally as US Fedwire shift and EU MiCA compliance align

Ripple expands RLUSD globally as US Fedwire shift and EU MiCA compliance align

July 15, 2025
Advertising

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

Advertising

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Advertising

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

The post North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates appeared first on CryptoSlate.

Check More Latest Cryptocurrency News Click Here– Latest Cryptocurrency News

Check More Business News Click Here– Latest Business News

Advertising

Related Posts

Bitcoin Bears Strike Back After ATH: Long/Short Ratio Flips Negative
Cryptocurrency

Bitcoin Bears Strike Back After ATH: Long/Short Ratio Flips Negative

July 15, 2025
Ripple expands RLUSD globally as US Fedwire shift and EU MiCA compliance align
Cryptocurrency

Ripple expands RLUSD globally as US Fedwire shift and EU MiCA compliance align

July 15, 2025
Ethereum Price July 2025: Trends, ETF Inflows & Forecasts
Cryptocurrency

Ethereum Price July 2025: Trends, ETF Inflows & Forecasts

July 15, 2025
Ripple and Circle Eye Bank Licenses as Stablecoin Legislation Gains Momentum – Crypto News Flash
Cryptocurrency

Ripple and Circle Eye Bank Licenses as Stablecoin Legislation Gains Momentum – Crypto News Flash

July 15, 2025
Metaplanet Doubles Down on Bitcoin with 797 BTC Buy at Record Highs
Cryptocurrency

Metaplanet Doubles Down on Bitcoin with 797 BTC Buy at Record Highs

July 14, 2025
Bitcoin Price Hits 0K Milestone — Bulls Make History Again
Cryptocurrency

Bitcoin Price Hits $120K Milestone — Bulls Make History Again

July 14, 2025
Urgent appeal to help defend Tornado Cash’s Roman Storm and the right to financial privacy
Cryptocurrency

Urgent appeal to help defend Tornado Cash’s Roman Storm and the right to financial privacy

July 14, 2025
Avalanche (AVAX) Gears Up For Breakout As Daily Transactions Hit 20 Million
Cryptocurrency

Avalanche (AVAX) Gears Up For Breakout As Daily Transactions Hit 20 Million

July 13, 2025
What’s Behind Stellar’s Massive 80% Jump This Past Week? – Crypto News Flash
Cryptocurrency

What’s Behind Stellar’s Massive 80% Jump This Past Week? – Crypto News Flash

July 13, 2025
Bitcoin Price Break Above 8,000 Just The Start, Analyst Unveils ‘Golden Number’
Cryptocurrency

Bitcoin Price Break Above $118,000 Just The Start, Analyst Unveils ‘Golden Number’

July 12, 2025

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc.

Follow us on social media:

Recent News

  • You’ve Probably Used this App at least Once – Delete It While You Still Can!
  • France’s PM wants to cut 2 public holidays to save money
  • Crackles DIY Diamond Painting Kit for Kids | Craft Activity for Kids 6-15 Years | Fun Educational Return Gift | Perfect for Birthday & Party Favors | Multi Pack of 12

Category

  • Brand Stories
  • Business
  • Cryptocurrency
  • Culture
  • Education
  • Entertainment
  • Environment
  • Health Trends
  • Latest News
  • Lifestyle
  • National
  • News
  • Opinion
  • Review
  • Science
  • Space
  • Sports
  • Technology
  • Travel
  • Uncategorized
  • World

Recent News

You’ve Probably Used this App at least Once – Delete It While You Still Can!

You’ve Probably Used this App at least Once – Delete It While You Still Can!

July 16, 2025
France’s PM wants to cut 2 public holidays to save money

France’s PM wants to cut 2 public holidays to save money

July 15, 2025
  • About
  • Advertise
  • Careers
  • Contact
  • Science
  • Environment
  • Education
  • Guest Post on News 4 Social

© 2025 News4Social - All Rights Reserved. Guild King Pvt. Ltd. News4Social.

No Result
View All Result
  • News
  • Business
  • National
  • Sports
  • Lifestyle
  • Travel
  • Opinion
  • Cryptocurrency
  • Entertainment

© 2025 News4Social - All Rights Reserved. Guild King Pvt. Ltd. News4Social.

Advertising
pixel