Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

BTC price holds gains, but lacks conviction as derivatives signal caution

May 1, 2026

Commodity or Security? Ripple CTO Emeritus Explains Key Distinction

May 1, 2026

LyondellBasell completes sale of select European strategic assessment assets | Web3Wire

May 1, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»North Korean Hackers Launch New Wave of npm Package Attacks
North Korean Hackers Launch New Wave of npm Package Attacks
Security and Privacy

North Korean Hackers Launch New Wave of npm Package Attacks

August 29, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A recent surge in malicious activity involving North Korean-linked threat groups has been identified by cybersecurity researchers, revealing a coordinated campaign targeting the npm ecosystem.

The campaign began on August 12 2024, and involved publishing malicious npm packages designed to infiltrate developer environments and steal sensitive data.

The newly discovered packages, including temp-etherscan-api, ethersscan-api and telegram-con, exhibit sophisticated tactics such as multi-stage obfuscated JavaScript that downloads additional malware from remote servers.

Malicious npm Packages

According to a blog post published by Phylum today, the malware includes Python scripts and a full Python interpreter, which search for data in cryptocurrency wallet browser extensions while establishing persistence on the affected systems. Notably, the qq-console package is attributed to a known North Korean campaign named “Contagious Interview.”

Researchers identified another package, helmet-validate, published on August 23 2024, which employs a different attack method. It inserts JavaScript code that retrieves and executes malicious code from a remote endpoint, ipcheck[.]cloud. This domain is linked to previous North Korean operations, including fake job campaigns using the mirotalk[.]net domain, highlighting a pattern of recurring tactics.

The most recent package, sass-notification, was published on August 27 2024, and is linked to the “Moonstone Sleet” campaign. This package uses obfuscated JavaScript to run scripts that download, decrypt and execute remote payloads while removing traces of malicious activity, leaving behind what appears to be harmless software.

Read more on North Korean cyber-threats: North Korean Hackers Spoofing Journalist Emails to Spy on Policy Experts

Increasing Exploitation of npm By Threat Actors

Phylum warned these attacks underscore the increasing exploitation of npm by threat actors to compromise developer systems. 

See also  Binance lawsuit: 61 cryptocurrencies are now seen as securities by the SEC

“The diversity and simultaneous deployment of these attack vectors reveal a coordinated and relentless campaign by North Korean-aligned threat actors,” the company said.

“These adversaries continuously exploit the inherent trust in the npm ecosystem to compromise developers, infiltrate companies and steal cryptocurrency or any other assets that could lead to illicit financial gains.”

Source link

attacks Hackers Korean launch North npm Package Wave
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Defillama Confirms April 2026 as Crypto’s Most-Hacked Month With 30 Incidents

May 1, 2026

North Korea Hit Twice And Snagged 76% Of 2026 Hack Value

April 30, 2026

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

April 29, 2026

Luxor Signs MicroBT Hardware Commitment Worth $100M Alongside Firmware Launch

April 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Top 10 Ethereum cloud mining platforms in 2024

September 10, 2024

Gemini’s Cameron Winklevoss slams DCG for denying involvement in failed Earn program

August 12, 2023

Court Says SEC Could Have Informed Coinbase That Exchange Was Violating Securities Law Prior to Public Listing

July 16, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

BTC price holds gains, but lacks conviction as derivatives signal caution

May 1, 2026

Commodity or Security? Ripple CTO Emeritus Explains Key Distinction

May 1, 2026

LyondellBasell completes sale of select European strategic assessment assets | Web3Wire

May 1, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,399.001.73%
  • ethereumEthereum(ETH)$2,285.870.88%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.380.40%
  • binancecoinBNB(BNB)$618.090.29%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$84.000.98%
  • tronTRON(TRX)$0.3257160.00%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.24%
  • dogecoinDogecoin(DOGE)$0.1086372.16%