No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Sunday, March 8, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Cryptocurrency

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

by TheAdviserMagazine
9 months ago
in Cryptocurrency
Reading Time: 3 mins read
A A
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
Share on FacebookShare on TwitterShare on LInkedIn


Nemo

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

Latest Alpha Market Report



Source link

Tags: CodecredentialstealingDevDormanthijacksKoreanNorthrepositoriesslipsupdatesWalletwaves
ShareTweetShare
Previous Post

Social security funds are running out, new data shows

Next Post

Nvidia and the AI boom helps Malaysia’s Nationgate debut on the Southeast Asia 500 with a 720% revenue surge

Related Posts

edit post
Bitcoin funding rates just flashed one of the bleakest signals in months before one macro number changed everything

Bitcoin funding rates just flashed one of the bleakest signals in months before one macro number changed everything

by TheAdviserMagazine
March 8, 2026
0

Bitcoin's derivatives market gave us the best explanation of this week's macro stress.Funding rates turned sharply negative, open interest stayed...

edit post
US Judge Throws out Lawsuit Against Binance and CZ Over Claims of Funding Linked to Violent Attacks

US Judge Throws out Lawsuit Against Binance and CZ Over Claims of Funding Linked to Violent Attacks

by TheAdviserMagazine
March 7, 2026
0

A federal judge dismissed claims tying Binance and its founder Changpeng Zhao (CZ) to terrorist attacks, delivering a significant legal...

edit post
Pundit Says XRP Price Could Reach ,000 By The End Of 2026 If This Happens

Pundit Says XRP Price Could Reach $1,000 By The End Of 2026 If This Happens

by TheAdviserMagazine
March 7, 2026
0

The possibility of a massive surge in the XRP price has been raised again following comments made by financial commentator...

edit post
Crypto Fear and Greed Index Stumbles Back to ‘Extreme Fear’ Territory

Crypto Fear and Greed Index Stumbles Back to ‘Extreme Fear’ Territory

by TheAdviserMagazine
March 7, 2026
0

The Crypto Fear and Greed Index, one of the most widely used gauges of crypto investor sentiment, has fallen back...

edit post
South Korea moves to exclude USDT, USDC from corporate crypto investment rules

South Korea moves to exclude USDT, USDC from corporate crypto investment rules

by TheAdviserMagazine
March 7, 2026
0

South Korea is preparing to open the crypto market to corporate investors, but stablecoins like USDT and USDC may be...

edit post
Bitcoin Difficulty Holds Flat As Hashrate Moves Sideways

Bitcoin Difficulty Holds Flat As Hashrate Moves Sideways

by TheAdviserMagazine
March 7, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure On-chain data shows the Bitcoin Difficulty has...

Next Post
edit post
Centuri Holdings (CTRI) Fell This Week. Here is Why.

Centuri Holdings (CTRI) Fell This Week. Here is Why.

edit post
Spot Solana ETF Appears On DTCC—When SEC Approval?

Spot Solana ETF Appears On DTCC—When SEC Approval?

  • Trending
  • Comments
  • Latest
edit post
Foreclosure Starts are Up 19%—These Counties are Seeing the Highest Distress

Foreclosure Starts are Up 19%—These Counties are Seeing the Highest Distress

February 24, 2026
edit post
North Carolina Updates How Wills Can Be Stored

North Carolina Updates How Wills Can Be Stored

February 10, 2026
edit post
Gasoline-starved California is turning to fuel from the Bahamas

Gasoline-starved California is turning to fuel from the Bahamas

February 15, 2026
edit post
Where Is My 2025 Oregon State Tax Refund

Where Is My 2025 Oregon State Tax Refund

February 13, 2026
edit post
7 States Reporting a Surge in Norovirus Cases

7 States Reporting a Surge in Norovirus Cases

February 22, 2026
edit post
2025 Delaware State Tax Refund – DE Tax Brackets

2025 Delaware State Tax Refund – DE Tax Brackets

February 16, 2026
edit post
Learn These 3 Japanese Secrets for a Longer and Happier Retirement

Learn These 3 Japanese Secrets for a Longer and Happier Retirement

0
edit post
Existing US Home Sales Collapse Despite Falling Mortgage Rates

Existing US Home Sales Collapse Despite Falling Mortgage Rates

0
edit post
Bitcoin funding rates just flashed one of the bleakest signals in months before one macro number changed everything

Bitcoin funding rates just flashed one of the bleakest signals in months before one macro number changed everything

0
edit post
Pennsylvania Seniors: 7 State Programs That Help Pay for Heat, Groceries, and Prescriptions

Pennsylvania Seniors: 7 State Programs That Help Pay for Heat, Groceries, and Prescriptions

0
edit post
US stocks fell, GIFT Nifty down 300 points and oil nears 0. How will stock market react on Monday?

US stocks fell, GIFT Nifty down 300 points and oil nears $100. How will stock market react on Monday?

0
edit post
Asana CEO Dan Rogers says getting a job in Silicon Valley isn’t harder for Gen Z than it was for him

Asana CEO Dan Rogers says getting a job in Silicon Valley isn’t harder for Gen Z than it was for him

0
edit post
Pennsylvania Seniors: 7 State Programs That Help Pay for Heat, Groceries, and Prescriptions

Pennsylvania Seniors: 7 State Programs That Help Pay for Heat, Groceries, and Prescriptions

March 8, 2026
edit post
Bitcoin funding rates just flashed one of the bleakest signals in months before one macro number changed everything

Bitcoin funding rates just flashed one of the bleakest signals in months before one macro number changed everything

March 8, 2026
edit post
Asana CEO Dan Rogers says getting a job in Silicon Valley isn’t harder for Gen Z than it was for him

Asana CEO Dan Rogers says getting a job in Silicon Valley isn’t harder for Gen Z than it was for him

March 8, 2026
edit post
Outbound flights resume from Ben Gurion airport

Outbound flights resume from Ben Gurion airport

March 8, 2026
edit post
US stocks fell, GIFT Nifty down 300 points and oil nears 0. How will stock market react on Monday?

US stocks fell, GIFT Nifty down 300 points and oil nears $100. How will stock market react on Monday?

March 8, 2026
edit post
China says ‘thorough preparations’ needed ahead of Trump-Xi meeting

China says ‘thorough preparations’ needed ahead of Trump-Xi meeting

March 8, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Pennsylvania Seniors: 7 State Programs That Help Pay for Heat, Groceries, and Prescriptions
  • Bitcoin funding rates just flashed one of the bleakest signals in months before one macro number changed everything
  • Asana CEO Dan Rogers says getting a job in Silicon Valley isn’t harder for Gen Z than it was for him
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.