• About Us
  • Careers
  • Contact
No Result
View All Result
Saturday, October 11, 2025
DeFi Planet
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Market Analysis
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverse
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Market Analysis
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverse
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
No Result
View All Result
DeFi Planet
No Result
View All Result
Home News Crypto

Lazarus Group Deploys Malicious npm Packages to Steal Credentials and Crypto Data

12 March 2025
in Crypto, News
Reading Time: 3 mins read
109 5
source: bleepingcomputer.com

source: bleepingcomputer.com

North Korea’s state-backed hacking group, Lazarus, has launched a fresh supply chain attack, injecting six malicious npm packages designed to steal credentials and exfiltrate cryptocurrency data.

The campaign, uncovered by the Socket Research Team, leverages BeaverTail malware to infiltrate developers’ systems and extract sensitive information.

According to the researchers, the compromised packages—is-buffer-validator, yoojae-validator, event-handle-package, array-empty-validator, react-event-dependency, and auth-validator—were downloaded over 300 times before detection. These packages rely on typosquatting, mimicking legitimate libraries to trick developers into installing them. Once executed, they scan browser profiles from Chrome, Brave, and Firefox, as well as macOS keychain data, to harvest login credentials and cryptocurrency wallet details, particularly those related to Solana and Exodus wallets.

The stolen data is transmitted to a hardcoded command-and-control (C2) server at hxxp://172.86.84[.]38:1224/uploads, aligning with Lazarus’s known tactics of persistent access and data exfiltration. Kirill Boychenko, a threat intelligence analyst at Socket Security, emphasized that this attack follows Lazarus’s established pattern of leveraging multi-stage payloads to infiltrate systems and maintain access over time.

Lazarus has a history of exploiting supply chain vulnerabilities, previously targeting npm, GitHub, and PyPI to compromise networks. The group was recently linked to the $1.46 billion Bybit exchange hack in late February, which is considered one of the largest cryptocurrency thefts. Reports suggest the attack originated from a compromised computer at Safe, Bybit’s technology provider, allowing hackers to siphon funds. 

Bybit’s CEO, Ben Zhou, later revealed that 20% of the stolen assets had already become untraceable due to laundering via crypto-mixing services. Zhou noted that about 77% of the stolen assets remain traceable, but the laundered portion complicates recovery efforts. The attackers primarily utilized THORChain, a cross-chain liquidity protocol, to convert stolen Ethereum into Bitcoin. Zhou also revealed that 11 parties, including Mantle, ParaSwap, and blockchain investigator ZachXBT, have assisted in recovering some funds, with over $2.1 million in bounties paid out.

 

If you want to read more news articles like this, visit DeFi Planet and follow us on Twitter, LinkedIn, Facebook, Instagram, and CoinMarketCap Community.

“Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

Tags: Lazarus GroupNorth Korea
Share66Tweet41Share12
Favour Okosodo

Favour Okosodo

Experienced web content writer with a strong command of SEO, specializing in creating concise, engaging content that drives traffic and enhances conversions across diverse industries.

Related Posts

Bithumb Lists Aster (ASTER) on KRW Market With Zero Trading Fees
Crypto

Bithumb Lists Aster (ASTER) on KRW Market With Zero Trading Fees

10 October 2025
Bybit Secures UAE’s First Full Virtual Asset License, Strengthening Global Crypto Expansion
Crypto

Bybit Secures UAE’s First Full Virtual Asset License, Strengthening Global Crypto Expansion

10 October 2025
Coinbase and Mastercard Compete for $2B Acquisition of Stablecoin Fint8ech BVNK
News

Coinbase and Mastercard Compete for $2B Acquisition of Stablecoin Fint8ech BVNK

10 October 2025
Institutional Investors See Tokenized Assets Powering Portfolios by 2030 — State Street
Crypto

Institutional Investors See Tokenized Assets Powering Portfolios by 2030 — State Street

10 October 2025

Editors Picks

Web3 in 2025: Where We Are, What’s Next, and What the Data Says

Web3 in 2025: Where We Are, What’s Next, and What the Data Says

byOlayinka Sodiq
21 July 2025
0

What Is a Rebase Token and How Does It Work?

What Is a Rebase Token and How Does It Work?

byOlajumoke Oyaleke
28 June 2025
0

What Are DeFi Options Vaults, and How Do They Work?

What Are DeFi Options Vaults, and How Do They Work?

byOlajumoke Oyaleke
26 June 2025
0

What Are Teardrop Attacks in Crypto?

byOlajumoke Oyaleke
17 June 2025
0

What Are Fractional NFTs, and How Do They Work?

What Are Fractional NFTs, and How Do They Work?

byBlessing Lisafi
7 February 2024
0

Read More

Chain of Thoughts

The Aesthetics of Web3: Why Vibe Matters in Decentralized Communities

The Aesthetics of Web3: Why Vibe Matters in Decentralized Communities

byOlu Omoyele
27 September 2025
0

...

Zero-Knowledge Everything: Trust, Privacy, and Verification in the Digital Age

Zero-Knowledge Everything: Trust, Privacy, and Verification in the Digital Age

byOlu Omoyele
30 August 2025
0

...

What Happens When AI Gets a Wallet?

What Happens When AI Gets a Wallet?

byOlu Omoyele
31 July 2025
0

...

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

byOlu Omoyele
30 June 2025
0

...

Markets Update

Your Weekend Crypto Roundup | October 2025 (Week 2)

8 hours ago

Your Weekend Crypto Roundup | October 2025 (Week 1)

1 week ago

What $1 Billion in Liquidations Means for Market Stability

1 week ago

Why Crypto’s Cross-Chain Future Depends on Regulatory Readiness

1 week ago

MicroStrategy’s Debt-Fueled Bitcoin Buys: Smart Treasury Move or Dangerous Precedent?

1 week ago

XRP Reserves Spiked by 1.2B: What Does This Mean for Market Adoption?

1 week ago
Read More

Events

  • No events
  • Spotlight

    All about Ethereum
    All about Algorand
    All about Bitcoin
    All about Gora

    Press Releases

    Eightco Holdings Inc. ($ORBS) Expands its Strategic Vision into the Enterprise

    bychainwire
    10 October 2025
    0

    Whale.io Launches Battlepass Season 3, Featuring $77,000 in Crypto Casino Rewards

    bychainwire
    10 October 2025
    0

    Dreamcash Celebrates 100,000 Waitlist Signups with Exclusive $50k Giveaway Series

    bychainwire
    9 October 2025
    0

    Bybit Secures UAE’s First Virtual Asset Platform Operator License from Securities and Commodities Authority

    bychainwire
    9 October 2025
    0

    BTCC Exchange Hits 10M Users and $1.15T Q3 Trading Volume, Accelerating Global Expansion

    bychainwire
    9 October 2025
    0

    Read More

    ADVERTISING

    ABOUT

    TEAM

    CAREERS

    CONTACT

    TERMS & CONDITIONS

    PRIVACY POLICY

    © Copyright 2025 DeFi Planet

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • News
      • People
      • Business
      • Crime
      • Regulation
      • Crypto
      • CBDC
    • Market Analysis
      • Bitcoin
      • Ethereum
      • Stablecoins
      • Altcoins
      • Crypto ETFs
      • Memecoins
    • Policy
    • Articles
      • Press Releases
      • Opinion
      • Explainers
      • Guest Post
      • Sponsored
    • Directory
      • Companies
      • People
      • Products
      • Wallets
    • Multimedia
      • Videos
      • Podcasts
    • Learn
      • DeFi Basics
      • Tutorials
      • Reviews
      • Blockchain Fundamentals
    • Research
      • Case Studies
    • Explore
      • DeFi
      • Crypto Gaming
      • NFT
      • DAO
      • Metaverse
      • Glossary
    • Jobs
    • Markets Pro
      • DeFi Planet Pro
      • Spend Crypto
      • Swap Crypto
      • Coin Prices
      • Crypto Exchanges
      • Crypto Analyzer

    © Copyright 2024 DeFi Planet   |   Terms & Conditions   |   Privacy Policy

    -
    00:00
    00:00

    Queue

    Update Required Flash plugin
    -
    00:00
    00:00