• About Us
  • Careers
  • Contact
No Result
View All Result
Friday, July 18, 2025
DeFi Planet
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
No Result
View All Result
DeFi Planet
No Result
View All Result
Home News Crypto

Lazarus Group Deploys Malicious npm Packages to Steal Credentials and Crypto Data

12 March 2025
in Crypto, News
Reading Time: 3 mins read
109 4
source: bleepingcomputer.com

source: bleepingcomputer.com

North Korea’s state-backed hacking group, Lazarus, has launched a fresh supply chain attack, injecting six malicious npm packages designed to steal credentials and exfiltrate cryptocurrency data.

The campaign, uncovered by the Socket Research Team, leverages BeaverTail malware to infiltrate developers’ systems and extract sensitive information.

According to the researchers, the compromised packages—is-buffer-validator, yoojae-validator, event-handle-package, array-empty-validator, react-event-dependency, and auth-validator—were downloaded over 300 times before detection. These packages rely on typosquatting, mimicking legitimate libraries to trick developers into installing them. Once executed, they scan browser profiles from Chrome, Brave, and Firefox, as well as macOS keychain data, to harvest login credentials and cryptocurrency wallet details, particularly those related to Solana and Exodus wallets.

The stolen data is transmitted to a hardcoded command-and-control (C2) server at hxxp://172.86.84[.]38:1224/uploads, aligning with Lazarus’s known tactics of persistent access and data exfiltration. Kirill Boychenko, a threat intelligence analyst at Socket Security, emphasized that this attack follows Lazarus’s established pattern of leveraging multi-stage payloads to infiltrate systems and maintain access over time.

Lazarus has a history of exploiting supply chain vulnerabilities, previously targeting npm, GitHub, and PyPI to compromise networks. The group was recently linked to the $1.46 billion Bybit exchange hack in late February, which is considered one of the largest cryptocurrency thefts. Reports suggest the attack originated from a compromised computer at Safe, Bybit’s technology provider, allowing hackers to siphon funds. 

Bybit’s CEO, Ben Zhou, later revealed that 20% of the stolen assets had already become untraceable due to laundering via crypto-mixing services. Zhou noted that about 77% of the stolen assets remain traceable, but the laundered portion complicates recovery efforts. The attackers primarily utilized THORChain, a cross-chain liquidity protocol, to convert stolen Ethereum into Bitcoin. Zhou also revealed that 11 parties, including Mantle, ParaSwap, and blockchain investigator ZachXBT, have assisted in recovering some funds, with over $2.1 million in bounties paid out.

 

If you want to read more news articles like this, visit DeFi Planet and follow us on Twitter, LinkedIn, Facebook, Instagram, and CoinMarketCap Community.

“Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

Don't miss out!

Subscribe To Our Newsletter

Receive top education news, lesson ideas, teaching tips and more!
Invalid email address
Give it a try. You can unsubscribe at any time.
Thanks for subscribing!
Tags: Lazarus GroupNorth Korea
Share66Tweet41Share12
Favour Okosodo

Favour Okosodo

Experienced web content writer with a strong command of SEO, specializing in creating concise, engaging content that drives traffic and enhances conversions across diverse industries.

Related Posts

source: pandofinance.com
Bitcoin

Pando Launches Bitcoin ETF in Hong Kong

18 July 2025
source: coinmarketcap.com
Crypto

Global Crypto Market Cap Surpasses $4 Trillion, Marking New Era of Institutional Adoption and Altcoin Growth

18 July 2025
source: theblock.co
Crypto

Backpack Unveils Platform to Connect FTX Creditors with Debt Claim Buyers

18 July 2025
source: coindoo.com
Bitcoin

BTC Digital Dumps Bitcoin for Ethereum in Radical Treasury Pivot

18 July 2025

Featured Posts

What is a Crypto Order Book and How Does it Work?

What is a Crypto Order Book and How Does it Work?

byOlayinka Sodiq
14 July 2025
0

Elon Musk's xAI Colossus: What It Is and Why It’s a Big Deal?

Elon Musk’s xAI Colossus: What It Is and Why It’s a Big Deal?

byOlayinka Sodiqand1 others
12 July 2025
0

Is AI the Future of Crypto Trading or a Threat to Market Stability?

Is AI the Future of Crypto Trading or a Threat to Market Stability?

byOlajumoke Oyaleke
7 July 2025
0

What Are DeFi Options Vaults, and How Do They Work?

What Are DeFi Options Vaults, and How Do They Work?

byOlajumoke Oyaleke
26 June 2025
0

source: investorplace.com

How to Find the Newest Cryptocurrencies Before They’re Listed

byOlayinka Sodiq
30 December 2024
0

Read More

Chain of Thoughts

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

byOlu Omoyele
30 June 2025
0

...

Are Stablecoins Bank Deposits?

Are Stablecoins Bank Deposits?

byOlu Omoyele
31 May 2025
0

...

DAOs and the Coordination of Human Endeavour

DAOs and The Coordination of Human Endeavour

byOlu Omoyele
27 April 2025
0

...

Should DeFi Be Regulated?

Should DeFi Be Regulated?

byOlu Omoyele
27 March 2025
0

...

Markets Update

Account Abstraction Adoption: Are Users Ready for Smart Wallets?

2 days ago

The Role of Real-World Assets (RWAs) in the Next DeFi Boom

3 days ago

Stablecoins in 2025: Still Depegging or Finally Stable?

3 days ago

Your Weekend Crypto Roundup | July 2025 (Week 2)

1 week ago

The Battle for Web3 Infrastructure: Which Platforms are Dominating in Decentralized Storage, Compute, and Identity?

1 week ago

Is Ethereum Losing the Yield Battle?

1 week ago
Read More

Events

Rare Evo 2025
Rare Evo 2025
6 Aug 25
Las Vegas
CBDC Conference
CBDC Conference
9 Sep 25
Nassau

Spotlight

All about Ethereum
All about Algorand
All about Bitcoin
All about Gora

Press Releases

MultiBank Group to List $MBG Token on Gate.io and MEXC During Official Token Generation Event

bychainwire
18 July 2025
0

GSR Leads $100M Private Placement into Nasdaq-listed MEI Pharma to Launch First Institutional Litecoin Treasury Strategy Alongside Charlie Lee

bychainwire
18 July 2025
0

KuCoin Launches xStocks, Delivering a One-Stop Access Point to Top Global Tokenized Equities

bychainwire
18 July 2025
0

Streamex (BSGM) CEO Henry McPhie Highlights BSGM Merger and RWA Tokenization Strategy in Live TV Interview

bychainwire
17 July 2025
0

Numerai Announces $1M Strategic Buyback of NMR

bychainwire
17 July 2025
0

Read More

ADVERTISING

ABOUT

TEAM

CAREERS

CONTACT

TERMS & CONDITIONS

PRIVACY POLICY

© Copyright 2025 DeFi Planet

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter and activate your license key for Cryptocurrency Widgets PRO plugin for unrestricted and full access of all premium features.

Add New Playlist

No Result
View All Result
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer

© Copyright 2024 DeFi Planet   |   Terms & Conditions   |   Privacy Policy

-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00