No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Tuesday, September 23, 2025
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

by TheAdviserMagazine
3 months ago
in Cryptocurrency
Reading Time: 3 mins read
A A
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
Share on FacebookShare on TwitterShare on LInkedIn


Nemo

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

Latest Alpha Market Report



Source link

Tags: CodecredentialstealingDevDormanthijacksKoreanNorthrepositoriesslipsupdatesWalletwaves
ShareTweetShare
Previous Post

Social security funds are running out, new data shows

Next Post

Centuri Holdings (CTRI) Fell This Week. Here is Why.

Related Posts

edit post
How 5 solo Bitcoin miners cashed in over 0K each in 2025

How 5 solo Bitcoin miners cashed in over $350K each in 2025

by TheAdviserMagazine
September 23, 2025
0

Five unlikely solo wins of Bitcoin miners in 2025 At a time when Bitcoin (BTC) mining is dominated by large-scale...

edit post
BlackRock and major firms report M outflows in Ethereum ETFs

BlackRock and major firms report $76M outflows in Ethereum ETFs

by TheAdviserMagazine
September 23, 2025
0

Key Takeaways Spot Ethereum ETFs recorded $76 million in outflows, reflecting continued volatility in investor interest. Major asset managers, including...

edit post
US And UK Announce Partnership For New Crypto Regulatory Framework

US And UK Announce Partnership For New Crypto Regulatory Framework

by TheAdviserMagazine
September 23, 2025
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The United States and the United Kingdom...

edit post
Avantis and Aster defy market downturn with impressive rallies

Avantis and Aster defy market downturn with impressive rallies

by TheAdviserMagazine
September 22, 2025
0

Tokens from emerging perpetual trading decentralized exchanges posted substantial gains over the past week while established platforms declined, suggesting capital...

edit post
Crypto.com Expands Institutional Custody Services With Exodus Partnership

Crypto.com Expands Institutional Custody Services With Exodus Partnership

by TheAdviserMagazine
September 22, 2025
0

In a move signaling a growing emphasis on institutional-grade safeguards, Exodus Movement has partnered with Crypto.com Custody Trust Company to...

edit post
Ripple Targets Tokenization, Stablecoins in XRPL DeFi Roadmap

Ripple Targets Tokenization, Stablecoins in XRPL DeFi Roadmap

by TheAdviserMagazine
September 22, 2025
0

Ripple has placed stablecoins and tokenized real-world assets (RWAs) at the center of its institutional DeFi strategy. The XRP Ledger...

Next Post
edit post
Centuri Holdings (CTRI) Fell This Week. Here is Why.

Centuri Holdings (CTRI) Fell This Week. Here is Why.

edit post
Spot Solana ETF Appears On DTCC—When SEC Approval?

Spot Solana ETF Appears On DTCC—When SEC Approval?

  • Trending
  • Comments
  • Latest
edit post
What Happens If a Spouse Dies Without a Will in North Carolina?

What Happens If a Spouse Dies Without a Will in North Carolina?

September 14, 2025
edit post
California May Reimplement Mask Mandates

California May Reimplement Mask Mandates

September 5, 2025
edit post
Who Needs a Trust Instead of a Will in North Carolina?

Who Needs a Trust Instead of a Will in North Carolina?

September 1, 2025
edit post
Does a Will Need to Be Notarized in North Carolina?

Does a Will Need to Be Notarized in North Carolina?

September 8, 2025
edit post
DACA recipients no longer eligible for Marketplace health insurance and subsidies

DACA recipients no longer eligible for Marketplace health insurance and subsidies

September 11, 2025
edit post
Big Dave’s Cheesesteaks CEO grew up in ‘survival mode’ selling newspapers and bean pies—now his chain sells a  cheesesteak every 58 seconds

Big Dave’s Cheesesteaks CEO grew up in ‘survival mode’ selling newspapers and bean pies—now his chain sells a $12 cheesesteak every 58 seconds

August 30, 2025
edit post
The Liberal 19th Century – Econlib

The Liberal 19th Century – Econlib

0
edit post
How 5 solo Bitcoin miners cashed in over 0K each in 2025

How 5 solo Bitcoin miners cashed in over $350K each in 2025

0
edit post
Restaurant visits drop as Canadians tighten wallets

Restaurant visits drop as Canadians tighten wallets

0
edit post
Medicap Healthcare files papers with Sebi for Rs 240-cr IPO

Medicap Healthcare files papers with Sebi for Rs 240-cr IPO

0
edit post
Lennar (LEN) 3Q25: Lower prices and lower costs needed for affordability

Lennar (LEN) 3Q25: Lower prices and lower costs needed for affordability

0
edit post
Wall Street strategists chase S&P 500 like few times in history

Wall Street strategists chase S&P 500 like few times in history

0
edit post
How 5 solo Bitcoin miners cashed in over 0K each in 2025

How 5 solo Bitcoin miners cashed in over $350K each in 2025

September 23, 2025
edit post
The Liberal 19th Century – Econlib

The Liberal 19th Century – Econlib

September 23, 2025
edit post
Wall Street strategists chase S&P 500 like few times in history

Wall Street strategists chase S&P 500 like few times in history

September 23, 2025
edit post
Medicap Healthcare files papers with Sebi for Rs 240-cr IPO

Medicap Healthcare files papers with Sebi for Rs 240-cr IPO

September 23, 2025
edit post
Texhibition sees 6.7% uplift on March edition

Texhibition sees 6.7% uplift on March edition

September 23, 2025
edit post
How Equal Protection Laws Threaten Free Speech

How Equal Protection Laws Threaten Free Speech

September 23, 2025
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • How 5 solo Bitcoin miners cashed in over $350K each in 2025
  • The Liberal 19th Century – Econlib
  • Wall Street strategists chase S&P 500 like few times in history
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.