CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: Lazarus Infects New Batch of JavaScript Packages With Crypto Stealing Malware: Researchers
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > Lazarus Infects New Batch of JavaScript Packages With Crypto Stealing Malware: Researchers
News

Lazarus Infects New Batch of JavaScript Packages With Crypto Stealing Malware: Researchers

CoinRSS
Last updated: March 13, 2025 3:26 am
CoinRSS Published March 13, 2025
Share

In a new attack, North Korea’s Lazarus group has been linked to six fresh malicious npm packages.

Discovered by The Socket Research Team, the latest attack tries to deploy backdoors to steal credentials.

Lazarus is the infamous North Korean hacker group that’s been linked to the recent $1.4 billion Bybit hack,  $41 million hack of crypto casino Stake, and a $27 million hack of crypto exchange CoinEx, and countless others in the crypto industry.

The group was also initially linked to the $235 million hack of India crypto exchange WazirX in July 2024. But last month, the Delhi Police’s Intelligence Fusion and Strategic Operations (IFSO) division arrested a Bengal man and seized three laptops in connection with the exploit.

This new round of malware linked to Lazarus could also extract cryptocurrency data, stealing sensitive data from Solana and Exodus crypto wallets. The attack works by targeting files in Google Chrome, Brave and Firefox browsers, as well as keychain data on macOS, specifically targeting developers who might unknowingly install the packages.

“Attributing this attack definitively to Lazarus or a sophisticated copycat remains challenging, as absolute attribution is inherently difficult,” wrote Kirill Boychenko, threat intelligence analyst at Socket Security, in a blog post. “However, the tactics, techniques, and procedures (TTPs) observed in this npm attack closely align with Lazarus’s known operations, extensively documented by researchers from Unit42, eSentire, DataDog, Phylum, and others since 2022.”

The six packages that have been identified are: is-buffer-validator, yoojae-validator, event-handle-package, array-empty-validator, react-event-dependency, and auth-validator. These work by using typosquatting, with misspelled names, to trick developers into installing them.

According to Boychenko: “The APT group created and maintained GitHub repositories for five of the malicious packages, lending an appearance of open source legitimacy and increasing the likelihood of the harmful code being integrated into developer workflows.”

The packages have been collectively downloaded over 330 times and, at time of publishing, The Socket Team has petitioned for their removal having reported the GitHub repositories and user accounts.

This type of technique has been used by Lazarusin the past, with a Bybit exchange heist valuing a loss of around $1.4 billion in Ethereum. About  20 percent of those stolen funds have become untraceable.

In a statement, Bybit CEO, Ben Zhou, said: “77% are still traceable, 20% have gone dark, 3% have been frozen.”

Boychenko says: “The group’s tactics align with past campaigns leveraging multi-stage payloads to maintain long-term access, the cybersecurity experts note.”

Edited by James Rubin.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.

Source link

You Might Also Like

The Biggest Games Releasing in March 2025

California Judge Dismisses Dfinity Investor Suit For Being ‘Time-Barred’

Bitcoin: What Funding Rates say about a possible BTC price bottom

Bitcoin faces vital $96K test – Will BTC rally to $103K or fall to $95K?

Will the Nintendo Switch 2 Be Too Big?

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article U.S. House votes ‘292-132’ to overturn IRS DeFi rule – Details here
Next Article Ethereum price prediction: When could traders look to go short?
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
Solana ETF filings now include staking – Approval odds soar to 91%
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?