No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Monday, February 2, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

by TheAdviserMagazine
8 months ago
in Cryptocurrency
Reading Time: 3 mins read
A A
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
Share on FacebookShare on TwitterShare on LInkedIn


Nemo

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

Latest Alpha Market Report



Source link

Tags: CodecredentialstealingDevDormanthijacksKoreanNorthrepositoriesslipsupdatesWalletwaves
ShareTweetShare
Previous Post

Social security funds are running out, new data shows

Next Post

Nvidia and the AI boom helps Malaysia’s Nationgate debut on the Southeast Asia 500 with a 720% revenue surge

Related Posts

edit post
ISM Manufacturing PMI Rise is Bullish For Bitcoin

ISM Manufacturing PMI Rise is Bullish For Bitcoin

by TheAdviserMagazine
February 2, 2026
0

A metric tracking the health of the US economy has just posted its highest monthly score since August 2022, and...

edit post
Trump announces India trade deal lowering tariffs to 18% as equities bounce on Monday

Trump announces India trade deal lowering tariffs to 18% as equities bounce on Monday

by TheAdviserMagazine
February 2, 2026
0

President Donald Trump announced a new trade deal with India on Monday, lowering the US reciprocal tariff on Indian goods...

edit post
Epstein Leaks Shake BTC vs. XRP Rivalry

Epstein Leaks Shake BTC vs. XRP Rivalry

by TheAdviserMagazine
February 2, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Shadows of the past impact today. The...

edit post
Top Privacy Coins Poised to Lead the Next Crypto Bull Run

Top Privacy Coins Poised to Lead the Next Crypto Bull Run

by TheAdviserMagazine
February 2, 2026
0

Join Our Telegram channel to stay up to date on breaking news coverage The cryptocurrency market is navigating a severe...

edit post
CoinGape Announces Winners of Crypto Impact Awards 2025

CoinGape Announces Winners of Crypto Impact Awards 2025

by TheAdviserMagazine
February 2, 2026
0

CoinGape, on January 29, announced the winners of the long-awaited Crypto Impact Awards 2025. The CoinGape Awards recognised projects, companies,...

edit post
Binance commits to gigantic Bitcoin purchase as an implicit apology for October liquidation meltdown

Binance commits to gigantic Bitcoin purchase as an implicit apology for October liquidation meltdown

by TheAdviserMagazine
February 2, 2026
0

Binance just turned its emergency insurance fund into a public, auditable pledge. And it reads like a crisis-repair letter in...

Next Post
edit post
Centuri Holdings (CTRI) Fell This Week. Here is Why.

Centuri Holdings (CTRI) Fell This Week. Here is Why.

edit post
Spot Solana ETF Appears On DTCC—When SEC Approval?

Spot Solana ETF Appears On DTCC—When SEC Approval?

  • Trending
  • Comments
  • Latest
edit post
Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a 8 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

Most People Buy Mansions But This Virginia Lottery Winner Took the Lump Sum From a $348 Million Jackpot and Bought a Zero-Turn Lawn Mower Instead

January 10, 2026
edit post
Utility Shutoff Policies Are Changing in Several Midwestern States

Utility Shutoff Policies Are Changing in Several Midwestern States

January 9, 2026
edit post
80-year-old Home Depot rival shuts down location, no bankruptcy

80-year-old Home Depot rival shuts down location, no bankruptcy

January 4, 2026
edit post
Tennessee theater professor reinstated, with 0,000 settlement, after losing his job over a Charlie Kirk-related social media post

Tennessee theater professor reinstated, with $500,000 settlement, after losing his job over a Charlie Kirk-related social media post

January 8, 2026
edit post
Florida Snowbirds Are Running Into Residency Documentation Problems

Florida Snowbirds Are Running Into Residency Documentation Problems

January 10, 2026
edit post
I run one of America’s most successful remote work programs and the critics are right. Their solutions are all wrong, though

I run one of America’s most successful remote work programs and the critics are right. Their solutions are all wrong, though

January 11, 2026
edit post
Trump Floats Personal Residence Depreciation—A Big Move That Can Unlock Savings For Investors

Trump Floats Personal Residence Depreciation—A Big Move That Can Unlock Savings For Investors

0
edit post
I’m a 66-year-old retired homeowner in Fort Worth, sitting on 3,000 in cash. What should I do with my money?

I’m a 66-year-old retired homeowner in Fort Worth, sitting on $143,000 in cash. What should I do with my money?

0
edit post
FPI investments in primary market nearly halve in FY26

FPI investments in primary market nearly halve in FY26

0
edit post
Trump’s Mask of Unreality Slipping In the Face of the Epstein Files

Trump’s Mask of Unreality Slipping In the Face of the Epstein Files

0
edit post
ISM Manufacturing PMI Rise is Bullish For Bitcoin

ISM Manufacturing PMI Rise is Bullish For Bitcoin

0
edit post
10 of the Best High-Paying Retail Jobs

10 of the Best High-Paying Retail Jobs

0
edit post
FPI investments in primary market nearly halve in FY26

FPI investments in primary market nearly halve in FY26

February 2, 2026
edit post
ISM Manufacturing PMI Rise is Bullish For Bitcoin

ISM Manufacturing PMI Rise is Bullish For Bitcoin

February 2, 2026
edit post
Why some women go gray gracefully while others look washed out: a colorist explains

Why some women go gray gracefully while others look washed out: a colorist explains

February 2, 2026
edit post
‘We are an n of 1’: Palantir hails ‘incredible’ earnings as stock rockets nearly 8% after hours

‘We are an n of 1’: Palantir hails ‘incredible’ earnings as stock rockets nearly 8% after hours

February 2, 2026
edit post
Medicare Savings Programs Are Accepting New Applications Again

Medicare Savings Programs Are Accepting New Applications Again

February 2, 2026
edit post
Ask an Advisor: The future of legacy CRMs in an AI world

Ask an Advisor: The future of legacy CRMs in an AI world

February 2, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • FPI investments in primary market nearly halve in FY26
  • ISM Manufacturing PMI Rise is Bullish For Bitcoin
  • Why some women go gray gracefully while others look washed out: a colorist explains
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.