• About Us
  • Careers
  • Contact
No Result
View All Result
Wednesday, June 18, 2025
DeFi Planet
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
No Result
View All Result
DeFi Planet
No Result
View All Result

Lazarus Group Deploys Malicious npm Packages to Steal Credentials and Crypto Data

12 March 2025
in Crypto, News
Reading Time: 3 mins read
109 4
Home News Crypto

North Korea’s state-backed hacking group, Lazarus, has launched a fresh supply chain attack, injecting six malicious npm packages designed to steal credentials and exfiltrate cryptocurrency data.

The campaign, uncovered by the Socket Research Team, leverages BeaverTail malware to infiltrate developers’ systems and extract sensitive information.

According to the researchers, the compromised packages—is-buffer-validator, yoojae-validator, event-handle-package, array-empty-validator, react-event-dependency, and auth-validator—were downloaded over 300 times before detection. These packages rely on typosquatting, mimicking legitimate libraries to trick developers into installing them. Once executed, they scan browser profiles from Chrome, Brave, and Firefox, as well as macOS keychain data, to harvest login credentials and cryptocurrency wallet details, particularly those related to Solana and Exodus wallets.

The stolen data is transmitted to a hardcoded command-and-control (C2) server at hxxp://172.86.84[.]38:1224/uploads, aligning with Lazarus’s known tactics of persistent access and data exfiltration. Kirill Boychenko, a threat intelligence analyst at Socket Security, emphasized that this attack follows Lazarus’s established pattern of leveraging multi-stage payloads to infiltrate systems and maintain access over time.

Lazarus has a history of exploiting supply chain vulnerabilities, previously targeting npm, GitHub, and PyPI to compromise networks. The group was recently linked to the $1.46 billion Bybit exchange hack in late February, which is considered one of the largest cryptocurrency thefts. Reports suggest the attack originated from a compromised computer at Safe, Bybit’s technology provider, allowing hackers to siphon funds. 

Bybit’s CEO, Ben Zhou, later revealed that 20% of the stolen assets had already become untraceable due to laundering via crypto-mixing services. Zhou noted that about 77% of the stolen assets remain traceable, but the laundered portion complicates recovery efforts. The attackers primarily utilized THORChain, a cross-chain liquidity protocol, to convert stolen Ethereum into Bitcoin. Zhou also revealed that 11 parties, including Mantle, ParaSwap, and blockchain investigator ZachXBT, have assisted in recovering some funds, with over $2.1 million in bounties paid out.

 

If you want to read more news articles like this, visit DeFi Planet and follow us on Twitter, LinkedIn, Facebook, Instagram, and CoinMarketCap Community.

“Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

Don't miss out!

Subscribe To Our Newsletter

Receive top education news, lesson ideas, teaching tips and more!
Invalid email address
Give it a try. You can unsubscribe at any time.
Thanks for subscribing!
Tags: Lazarus GroupNorth Korea
Share66Tweet41Share12
Previous Post

Coinbase Secures Regulatory Approval to Re-Enter Indian Crypto Market

Next Post

SEC Acknowledges Nasdaq’s Proposal to List Grayscale Hedera Trust Shares

Favour Okosodo

Favour Okosodo

Experienced web content writer with a strong command of SEO, specializing in creating concise, engaging content that drives traffic and enhances conversions across diverse industries.

Related Posts

source: asiafundmanagers.com
News

JD.com to Launch HKD-Backed Stablecoin for Shopping

18 June 2025
source: ois.net
Crypto

Nasdaq-Listed Biotech Firm Eyenovia Invests $50 Million in Hyperliquid’s HYPE Token, Signals Major Crypto Push

18 June 2025
source: news.bitcoin.com
Crypto

SEC Opens Public Comments on Franklin Templeton’s Proposed XRP and Solana ETFs

18 June 2025
source: theblock.co
Crypto

Gemini Fires Back at CFTC, Accuses Agency of Misconduct and Bias in 2022 Legal Dispute

18 June 2025

Featured Posts

The Rise of AI Thieves: Can Bots Steal Your Crypto?

The Rise of AI Thieves: Can Bots Steal Your Crypto?

byOlayinka Sodiq
3 June 2025
0

Why Most DeFi Projects Fail (And What Needs to Change)

Why Most DeFi Projects Fail (And What Needs to Change)

byOlajumoke Oyaleke
15 May 2025
0

Yield-Bearing Assets in DeFi: How Do They Work and How Can You Maximize Them

Yield-Bearing Assets in DeFi: How Do They Work and How Can You Maximize Them

byFaari Labinjoand1 others
14 May 2025
0

Can DeFi Insurance Products Solve the Problem of Rug Pulls?

Can DeFi Insurance Products Solve the Problem of Rug Pulls?

byOlajumoke Oyaleke
25 April 2025
0

DeepSeek vs. ChatGPT vs Gemini vs Claude: Which AI Model Should Use For Your Crypto Tasks?

DeepSeek vs. ChatGPT vs Gemini vs Claude: Which AI Model Should Use For Your Crypto Tasks?

byOlajumoke Oyaleke
24 April 2025
0

Read More

Chain of Thoughts

Are Stablecoins Bank Deposits?

Are Stablecoins Bank Deposits?

byOlu Omoyele
31 May 2025
0

...

DAOs and the Coordination of Human Endeavour

DAOs and The Coordination of Human Endeavour

byOlu Omoyele
27 April 2025
0

...

Should DeFi Be Regulated?

Should DeFi Be Regulated?

byOlu Omoyele
27 March 2025
0

...

Is Tokenization All That It’s Cracked Up To Be?

Is Tokenization All That It’s Cracked Up To Be?

byOlu Omoyele
26 February 2025
0

...

Markets Update

Your Weekend Crypto Roundup | June 2025 (Week 2)

5 days ago

Your Weekend Crypto Roundup | June 2025 (Week 1)

2 weeks ago

Your Weekend Crypto Roundup | May 2025 (Week 5)

3 weeks ago

Your Weekend Crypto Roundup | May 2025 (Week 4)

4 weeks ago

Your Weekend Crypto Roundup | May 2025 (Week 3)

1 month ago

Your Weekend Crypto Roundup | May 2025 (Week 2)

1 month ago
Read More

Events

  • No events
  • Spotlight

    All about Ethereum
    All about Algorand
    All about Bitcoin
    All about Gora

    Press Releases

    BitVault Raises $2M from GSR, Gemini, and Auros to Launch BTC-Backed Money

    bychainwire
    18 June 2025
    0

    TAC Raises $11.5M to Bring DeFi to Telegram’s Billion-User Ecosystem

    bychainwire
    18 June 2025
    0

    BTCC Exchange Celebrates 14th Anniversary with Launch of First-Ever User Badge Program

    bychainwire
    18 June 2025
    0

    R0AR Introduces Unified DeFi Platform for Token, Liquidity, and NFT Staking

    bychainwire
    17 June 2025
    0

    Avail Goes Full Stack to Capture $300bn Global Blockchain Infra Market

    bychainwire
    17 June 2025
    0

    Read More

    ADVERTISING

    ABOUT

    TEAM

    CAREERS

    CONTACT

    TERMS & CONDITIONS

    PRIVACY POLICY

    © Copyright 2025 DeFi Planet

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In
    Please enter and activate your license key for Cryptocurrency Widgets PRO plugin for unrestricted and full access of all premium features.

    Add New Playlist

    No Result
    View All Result
    • News
      • People
      • Business
      • Crime
      • Regulation
      • Crypto
      • CBDC
    • Markets
      • Bitcoin
      • Ethereum
      • Stablecoins
      • Altcoins
      • Crypto ETFs
      • Memecoins
    • Policy
    • Articles
      • Press Releases
      • Opinion
      • Explainers
      • Guest Post
      • Sponsored
    • Directory
      • Companies
      • People
      • Products
      • Wallets
    • Multimedia
      • Videos
      • Podcasts
    • Learn
      • DeFi Basics
      • Tutorials
      • Reviews
      • Blockchain Fundamentals
    • Research
      • Case Studies
    • Explore
      • DeFi
      • Crypto Gaming
      • NFT
      • DAO
      • Metaverses
    • Jobs
    • Markets Pro
      • DeFi Planet Pro
      • Spend Crypto
      • Swap Crypto
      • Coin Prices
      • Crypto Exchanges
      • Crypto Analyzer

    © Copyright 2024 DeFi Planet   |   Terms & Conditions   |   Privacy Policy

    -
    00:00
    00:00

    Queue

    Update Required Flash plugin
    -
    00:00
    00:00