Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Celsius founder Alex Mashinsky settles FTC case with $10M payment

May 1, 2026

Visa Adds Base, Polygon, Canton, Arc and Tempo to Stablecoin Settlement Program

May 1, 2026

XRP 2017 Breakout Replay? Analyst Drops Bold 1,992% Target

May 1, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»North Korean Hackers Launch New Wave of npm Package Attacks
North Korean Hackers Launch New Wave of npm Package Attacks
Security and Privacy

North Korean Hackers Launch New Wave of npm Package Attacks

August 29, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A recent surge in malicious activity involving North Korean-linked threat groups has been identified by cybersecurity researchers, revealing a coordinated campaign targeting the npm ecosystem.

The campaign began on August 12 2024, and involved publishing malicious npm packages designed to infiltrate developer environments and steal sensitive data.

The newly discovered packages, including temp-etherscan-api, ethersscan-api and telegram-con, exhibit sophisticated tactics such as multi-stage obfuscated JavaScript that downloads additional malware from remote servers.

Malicious npm Packages

According to a blog post published by Phylum today, the malware includes Python scripts and a full Python interpreter, which search for data in cryptocurrency wallet browser extensions while establishing persistence on the affected systems. Notably, the qq-console package is attributed to a known North Korean campaign named “Contagious Interview.”

Researchers identified another package, helmet-validate, published on August 23 2024, which employs a different attack method. It inserts JavaScript code that retrieves and executes malicious code from a remote endpoint, ipcheck[.]cloud. This domain is linked to previous North Korean operations, including fake job campaigns using the mirotalk[.]net domain, highlighting a pattern of recurring tactics.

The most recent package, sass-notification, was published on August 27 2024, and is linked to the “Moonstone Sleet” campaign. This package uses obfuscated JavaScript to run scripts that download, decrypt and execute remote payloads while removing traces of malicious activity, leaving behind what appears to be harmless software.

Read more on North Korean cyber-threats: North Korean Hackers Spoofing Journalist Emails to Spy on Policy Experts

Increasing Exploitation of npm By Threat Actors

Phylum warned these attacks underscore the increasing exploitation of npm by threat actors to compromise developer systems. 

See also  Nftperp Shuts Down V1 Beta, Promising Thrilling Launch Of V2

“The diversity and simultaneous deployment of these attack vectors reveal a coordinated and relentless campaign by North Korean-aligned threat actors,” the company said.

“These adversaries continuously exploit the inherent trust in the npm ecosystem to compromise developers, infiltrate companies and steal cryptocurrency or any other assets that could lead to illicit financial gains.”

Source link

attacks Hackers Korean launch North npm Package Wave
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Defillama Confirms April 2026 as Crypto’s Most-Hacked Month With 30 Incidents

May 1, 2026

North Korea Hit Twice And Snagged 76% Of 2026 Hack Value

April 30, 2026

Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto W

April 29, 2026

Luxor Signs MicroBT Hardware Commitment Worth $100M Alongside Firmware Launch

April 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

New York City Spa Gets Heat for Heating with Bitcoin Mining

June 22, 2023

New Core Scientific CEO says company will exit bankruptcy by year end

August 7, 2023

What is Base? 5 Key Features of Coinbase’s New L2 Blockchain

August 7, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Celsius founder Alex Mashinsky settles FTC case with $10M payment

May 1, 2026

Visa Adds Base, Polygon, Canton, Arc and Tempo to Stablecoin Settlement Program

May 1, 2026

XRP 2017 Breakout Replay? Analyst Drops Bold 1,992% Target

May 1, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$77,267.001.53%
  • ethereumEthereum(ETH)$2,282.300.82%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.380.13%
  • binancecoinBNB(BNB)$617.05-0.08%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$83.940.80%
  • tronTRON(TRX)$0.3262020.44%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.03-0.24%
  • dogecoinDogecoin(DOGE)$0.1079590.17%