Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Pundit Shares Why Most People Will Miss The XRP Run

June 1, 2026

Crumbs from the System: The U.S. “UFO Disclosure” Is a Joke Compared to What Dakila Has Already Proven

June 1, 2026

Pi Network price consolidates at $0.14 as CiDi Games’ beta app attracts more than 81,000 users

June 1, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»North Korea Targets Crypto Devs Through NPM Packages
North Korea Targets Crypto Devs Through NPM Packages
Security and Privacy

North Korea Targets Crypto Devs Through NPM Packages

February 13, 20254 Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Researchers have uncovered a highly sophisticated North Korean campaign to covertly distribute crypto-stealing malware via open source components.

SecurityScorecard said in a blog post published this morning that it suspects the infamous Lazarus Group of being behind the live campaign, dubbed Operation Marstech Mayhem. It has already claimed over 230 victims in the US, Europe and Asia.

It traced a new “Marstech1” implant back to the “SuccessFriend” GitHub profile, which has been committing malicious as well as genuine software to the developer platform since July 2024.

However, SecurityScorecard claimed the same actor is also spreading the malware via npm packages, which are popular among crypto and Web3 project developers.

Read more on Lazarus Group: Lazarus Group Targets Bitdefender Researcher with LinkedIn Recruiting Scam

Marstech1 scans systems for MetaMask, Exodus and Atomic wallets, modifying browser configuration files to inject silent payloads that can intercept transactions, SecurityScorecard said.

The risk is that developers may include it in legitimate software, thereby posing a risk to potentially millions of downstream users.

This is made more likely by the various efforts Lazarus has gone to in order to avoid static and dynamic analysis of Marstech1, including Base85 encoding and XOR decryption.

These techniques are slightly different to a previous iteration of the malicious JavaScript, which were observed in two attacks in late 2024 and Jan 2025.

This latest iteration used other techniques to ensure the malware would go unnoticed and slip into the software supply chain, including:

  • Control flow flattening and self-invoking functions
  • Random variable and function names
  • Base64 string encoding
  • Anti-debugging (anti-tampering checks)
  • Splitting and recombining strings
See also  Here’s what SOC 2 compliance audits mean for crypto projects

Lazarus Adapts Operations

In a sign of its growing sophistication, Lazarus Group is also adapting its infrastructure to throw security researchers off the scent.

The group is now using port 3000 for command-and-control (C2) communications, instead of ports 1224 and 1245, and is using Node.js Express backends instead of React-based control panels to, the report noted.

“Operation Marstech Mayhem exposes a critical evolution in the Lazarus Group’s supply chain attacks, demonstrating not only their commitment to operational stealth but also significant adaptability in implant development,” said SecurityScorecard SVP of threat research and intelligence, Ryan Sherstobitoff.

“It serves as a stark reminder that the landscape of cyber-threats is rapidly evolving. It is imperative for organizations and developers to adopt proactive security measures, continuously monitor supply chain activities and integrate advanced threat intelligence solutions to mitigate the risk of sophisticated implant-based attacks orchestrated by threat actors like the Lazarus Group.”

Source link

Crypto Devs Korea North npm Packages Targets
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Next Crypto Legislation Window Is 2030

June 1, 2026

JPMorgan CEO Jamie Dimon takes aim at the Clarity Act over crypto deposit risks

June 1, 2026

Coinbase makes a major play for India’s booming $3 billion crypto market with local currency launch

June 1, 2026

Texas man charged over alleged $12.3 million AI crypto arbitrage scam

May 31, 2026
View 4 Comments

4 Comments

  1. Merrill Sasser on February 15, 2025 12:07 am

    Some genuinely nice and utilitarian information on this website , likewise I believe the pattern has good features.

    Reply
  2. Prime biome review on March 15, 2025 5:19 am

    Merely wanna input that you have a very nice internet site, I love the design and style it actually stands out.

    Reply
  3. Caroline on April 15, 2025 4:09 pm

    Do you want to experience a really blonde free live webcams with girls? Not boring, but really hardcore sex? Then you have come to the right place with me. I go rock hard in my pussy with my big dildo and even take it anally deep.

    Reply
  4. crypto mining on May 10, 2025 4:22 am

    I am often to running a blog and i really admire your content. The article has actually peaks my interest. I’m going to bookmark your web site and keep checking for brand new information.

    Reply
Leave A Reply Cancel Reply

Top Posts

Jack Dorsey’s Square to Invest More in Bitcoin Mining and Shut Decentralized ‘Web5’ Venture

November 8, 2024

Here’s why South Koreans prefer XRP over Bitcoin and Ethereum

January 17, 2026

Terror funding still relies on traditional financial systems like cash, not crypto: Coinbase

October 19, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Pundit Shares Why Most People Will Miss The XRP Run

June 1, 2026

Crumbs from the System: The U.S. “UFO Disclosure” Is a Joke Compared to What Dakila Has Already Proven

June 1, 2026

Pi Network price consolidates at $0.14 as CiDi Games’ beta app attracts more than 81,000 users

June 1, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$71,403.00-2.74%
  • ethereumEthereum(ETH)$1,975.35-1.18%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$683.58-3.53%
  • rippleXRP(XRP)$1.29-2.61%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$80.22-1.57%
  • tronTRON(TRX)$0.346417-0.62%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.042.39%
  • HyperliquidHyperliquid(HYPE)$71.916.06%