No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Saturday, October 18, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

by TheAdviserMagazine
4 months ago
in Cryptocurrency
Reading Time: 3 mins read
A A
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
Share on FacebookShare on TwitterShare on LInkedIn


Nemo

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

Latest Alpha Market Report



Source link

Tags: CodecredentialstealingDevDormanthijacksKoreanNorthrepositoriesslipsupdatesWalletwaves
ShareTweetShare
Previous Post

Social security funds are running out, new data shows

Next Post

Centuri Holdings (CTRI) Fell This Week. Here is Why.

Related Posts

edit post
Rumors Circulate That Ripple Is Buying  Billion Worth Of XRP — Here’s What We Know

Rumors Circulate That Ripple Is Buying $1 Billion Worth Of XRP — Here’s What We Know

by TheAdviserMagazine
October 18, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Crypto firm Ripple is reportedly set to...

edit post
Bollinger Sees ‘W’ Bottom in Ethereum, Solana, Not Bitcoin

Bollinger Sees ‘W’ Bottom in Ethereum, Solana, Not Bitcoin

by TheAdviserMagazine
October 18, 2025
0

Famous technical analyst John Bollinger have found possible W bottoms in Ethereum (ETH) and Solana (SOL) charts. These are patterns...

edit post
how retail turned Bitcoin proxy plays into pain trade

how retail turned Bitcoin proxy plays into pain trade

by TheAdviserMagazine
October 18, 2025
0

There’s a grim symmetry to every crypto boom: an idea born from freedom eventually gets packaged, securitized, and sold back...

edit post
Altcoins Selling Pressure Persists As Exchange Inflow Hits 2025 High — Details

Altcoins Selling Pressure Persists As Exchange Inflow Hits 2025 High — Details

by TheAdviserMagazine
October 18, 2025
0

Altcoins have not quite recovered from the significant downturn that hit the financial markets a week ago. Most large-cap cryptocurrency...

edit post
DeFi Dev Corp Boosts Solana Holdings to 6 Million

DeFi Dev Corp Boosts Solana Holdings to $426 Million

by TheAdviserMagazine
October 18, 2025
0

DeFi Development Corp. has acquired 86,307 additional SOL at an average price of $110.91, increasing its total SOL holdings to...

edit post
Schwab Reports High Crypto Engagement Despite ETF Outflows

Schwab Reports High Crypto Engagement Despite ETF Outflows

by TheAdviserMagazine
October 18, 2025
0

Spot Bitcoin exchange-traded funds in the United States have seen more than $1.2 billion in outflows this week, but Charles...

Next Post
edit post
Centuri Holdings (CTRI) Fell This Week. Here is Why.

Centuri Holdings (CTRI) Fell This Week. Here is Why.

edit post
Spot Solana ETF Appears On DTCC—When SEC Approval?

Spot Solana ETF Appears On DTCC—When SEC Approval?

  • Trending
  • Comments
  • Latest
edit post
Pennsylvania House of Representatives Rejects Update to Child Custody Laws

Pennsylvania House of Representatives Rejects Update to Child Custody Laws

October 7, 2025
edit post
What to Do When a Loved One Dies in North Carolina

What to Do When a Loved One Dies in North Carolina

October 8, 2025
edit post
77-year-old popular furniture retailer closes store locations

77-year-old popular furniture retailer closes store locations

October 18, 2025
edit post
California Attorney Pleads Guilty For Role In 2M Ponzi Scheme

California Attorney Pleads Guilty For Role In $912M Ponzi Scheme

October 15, 2025
edit post
Baby Boomers Are Flocking to This Florida Town — but Not for the Weather

Baby Boomers Are Flocking to This Florida Town — but Not for the Weather

October 9, 2025
edit post
Probate vs. Non-Probate Assets: What’s the Difference?

Probate vs. Non-Probate Assets: What’s the Difference?

October 17, 2025
edit post
Rich and Broke: How Can Someone Approaching Retirement Who Owns Their House Outright and Has M in Savings Struggle With Money Month to Month?

Rich and Broke: How Can Someone Approaching Retirement Who Owns Their House Outright and Has $1M in Savings Struggle With Money Month to Month?

0
edit post
Dalal Street Week Ahead: Rising VIX signals hedging; traders advised tactical approach

Dalal Street Week Ahead: Rising VIX signals hedging; traders advised tactical approach

0
edit post
AI startups are leasing luxury apartments in San Francisco for staff and offering large rent stipends to attract talent 

AI startups are leasing luxury apartments in San Francisco for staff and offering large rent stipends to attract talent 

0
edit post
Protein Powders and Shakes Contain High Amounts of Lead, New Report Says – A Pharmacologist Explains the Data

Protein Powders and Shakes Contain High Amounts of Lead, New Report Says – A Pharmacologist Explains the Data

0
edit post
Rumors Circulate That Ripple Is Buying  Billion Worth Of XRP — Here’s What We Know

Rumors Circulate That Ripple Is Buying $1 Billion Worth Of XRP — Here’s What We Know

0
edit post
18% of US Households Are Millionaires. Here is Why You Aren’t One of Them.

18% of US Households Are Millionaires. Here is Why You Aren’t One of Them.

0
edit post
Rumors Circulate That Ripple Is Buying  Billion Worth Of XRP — Here’s What We Know

Rumors Circulate That Ripple Is Buying $1 Billion Worth Of XRP — Here’s What We Know

October 18, 2025
edit post
U.S. jury issues  million verdict against France’s largest bank over Sudanese atrocities

U.S. jury issues $20 million verdict against France’s largest bank over Sudanese atrocities

October 18, 2025
edit post
AI startups are leasing luxury apartments in San Francisco for staff and offering large rent stipends to attract talent 

AI startups are leasing luxury apartments in San Francisco for staff and offering large rent stipends to attract talent 

October 18, 2025
edit post
77-year-old popular furniture retailer closes store locations

77-year-old popular furniture retailer closes store locations

October 18, 2025
edit post
Bollinger Sees ‘W’ Bottom in Ethereum, Solana, Not Bitcoin

Bollinger Sees ‘W’ Bottom in Ethereum, Solana, Not Bitcoin

October 18, 2025
edit post
Ford CEO Jim Farley Warns Factory Workers Are Needed in the Hundreds of Thousands If America Is to Realize AI Dreams

Ford CEO Jim Farley Warns Factory Workers Are Needed in the Hundreds of Thousands If America Is to Realize AI Dreams

October 18, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Rumors Circulate That Ripple Is Buying $1 Billion Worth Of XRP — Here’s What We Know
  • U.S. jury issues $20 million verdict against France’s largest bank over Sudanese atrocities
  • AI startups are leasing luxury apartments in San Francisco for staff and offering large rent stipends to attract talent 
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.