No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Sunday, December 21, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

by TheAdviserMagazine
6 months ago
in Cryptocurrency
Reading Time: 3 mins read
A A
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
Share on FacebookShare on TwitterShare on LInkedIn


Nemo

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

Latest Alpha Market Report



Source link

Tags: CodecredentialstealingDevDormanthijacksKoreanNorthrepositoriesslipsupdatesWalletwaves
ShareTweetShare
Previous Post

Social security funds are running out, new data shows

Next Post

Nvidia and the AI boom helps Malaysia’s Nationgate debut on the Southeast Asia 500 with a 720% revenue surge

Related Posts

edit post
Tom Lee Breaks Down Fundstrat’s Position

Tom Lee Breaks Down Fundstrat’s Position

by TheAdviserMagazine
December 21, 2025
0

According to reports, Fundstrat analysts are sending mixed signals about Bitcoin’s path in 2026. One line of work inside the...

edit post
Nic Carter Says Bitcoin Devs Are ‘Sleepwalking’ Toward a Quantum Reckoning

Nic Carter Says Bitcoin Devs Are ‘Sleepwalking’ Toward a Quantum Reckoning

by TheAdviserMagazine
December 21, 2025
0

Bitcoin venture capitalist Nic Carter has reignited the debate over Bitcoin’s long-term security with a sweeping report on quantum computing...

edit post
Klarna Partners With Coinbase to Raise USDC Funding From Institutions

Klarna Partners With Coinbase to Raise USDC Funding From Institutions

by TheAdviserMagazine
December 21, 2025
0

Klarna, a Swedish fintech company known for its “Buy Now, Pay Later” (BNPL) service, has partnered with crypto exchange Coinbase...

edit post
Ethereum Foundation prioritizes security, targets 128-bit rule by 2026

Ethereum Foundation prioritizes security, targets 128-bit rule by 2026

by TheAdviserMagazine
December 20, 2025
0

Key Takeaways The Ethereum Foundation is prioritizing security over speed, aiming for 128-bit provable security by the end of 2026....

edit post
Blockchain Association Rejects Proposal To Widen Stablecoin Yield Restrictions

Blockchain Association Rejects Proposal To Widen Stablecoin Yield Restrictions

by TheAdviserMagazine
December 20, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The Blockchain Association led a broad industry...

edit post
Bitcoin struggles under liquidity pressure as market depth thins

Bitcoin struggles under liquidity pressure as market depth thins

by TheAdviserMagazine
December 20, 2025
0

Bitcoin’s inability to reclaim $90,000 is looking less like a debate about narratives and more like a test of market...

Next Post
edit post
Centuri Holdings (CTRI) Fell This Week. Here is Why.

Centuri Holdings (CTRI) Fell This Week. Here is Why.

edit post
Spot Solana ETF Appears On DTCC—When SEC Approval?

Spot Solana ETF Appears On DTCC—When SEC Approval?

  • Trending
  • Comments
  • Latest
edit post
How Long is a Last Will and Testament Valid in North Carolina?

How Long is a Last Will and Testament Valid in North Carolina?

December 8, 2025
edit post
In an Ohio Suburb, Sprawl Is Being Transformed Into Walkable Neighborhoods

In an Ohio Suburb, Sprawl Is Being Transformed Into Walkable Neighborhoods

December 14, 2025
edit post
Democrats Insist On Taxing Tips        

Democrats Insist On Taxing Tips        

December 15, 2025
edit post
Detroit Seniors Are Facing Earlier Shutoff Notices This Season

Detroit Seniors Are Facing Earlier Shutoff Notices This Season

December 20, 2025
edit post
Living Trusts in NC Explained: What You Should Know

Living Trusts in NC Explained: What You Should Know

December 16, 2025
edit post
How to Make a Valid Will in North Carolina

How to Make a Valid Will in North Carolina

November 20, 2025
edit post
When Can the IRS Pursue a Deceased Spouse’s Estate Without Probate? – Houston Tax Attorneys

When Can the IRS Pursue a Deceased Spouse’s Estate Without Probate? – Houston Tax Attorneys

0
edit post
A holiday cash flow solution gets a rate break

A holiday cash flow solution gets a rate break

0
edit post
Protecting a Societal Cancer with a Web of Lies

Protecting a Societal Cancer with a Web of Lies

0
edit post
Coinbase Asks Courts to Bar States From Regulating Prediction Markets

Coinbase Asks Courts to Bar States From Regulating Prediction Markets

0
edit post
7 Funeral Cost Surprises Families Discover in Winter

7 Funeral Cost Surprises Families Discover in Winter

0
edit post
CAG Earnings: Conagra Brands Q2 profit declines on lower sales

CAG Earnings: Conagra Brands Q2 profit declines on lower sales

0
edit post
Asian stocks rally: Asian stocks gain as hopes for year-end rally grow

Asian stocks rally: Asian stocks gain as hopes for year-end rally grow

December 21, 2025
edit post
Nicki Minaj calls Trump and Vance ‘role models’ for young men at Turning Point USA event

Nicki Minaj calls Trump and Vance ‘role models’ for young men at Turning Point USA event

December 21, 2025
edit post
Global Exposure With Major Differences

Global Exposure With Major Differences

December 21, 2025
edit post
Tom Lee Breaks Down Fundstrat’s Position

Tom Lee Breaks Down Fundstrat’s Position

December 21, 2025
edit post
Nic Carter Says Bitcoin Devs Are ‘Sleepwalking’ Toward a Quantum Reckoning

Nic Carter Says Bitcoin Devs Are ‘Sleepwalking’ Toward a Quantum Reckoning

December 21, 2025
edit post
3 Brilliant High-Yield Dividend Stocks to Buy Now and Hold for the Long Term

3 Brilliant High-Yield Dividend Stocks to Buy Now and Hold for the Long Term

December 21, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Asian stocks rally: Asian stocks gain as hopes for year-end rally grow
  • Nicki Minaj calls Trump and Vance ‘role models’ for young men at Turning Point USA event
  • Global Exposure With Major Differences
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.