Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Here is why Strategy's dividend-paying crypto stock is crashing to near-historic lows

June 16, 2026

HashKey Chain Partners Morpho to Blend Compliance and DeFi for Institutional CeDeFi and RWA Lending

June 16, 2026

Kraken Brings Regulated Perpetual Futures Onshore to US Users

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»North Korean Hackers Launch New Wave of npm Package Attacks
North Korean Hackers Launch New Wave of npm Package Attacks
Security

North Korean Hackers Launch New Wave of npm Package Attacks

March 3, 2026No Comments2 Mins Read

A recent surge in malicious activity involving North Korean-linked threat groups has been identified by cybersecurity researchers, revealing a coordinated campaign targeting the npm ecosystem.

The campaign began on August 12 2024, and involved publishing malicious npm packages designed to infiltrate developer environments and steal sensitive data.

The newly discovered packages, including temp-etherscan-api, ethersscan-api and telegram-con, exhibit sophisticated tactics such as multi-stage obfuscated JavaScript that downloads additional malware from remote servers.

Malicious npm Packages

According to a blog post published by Phylum today, the malware includes Python scripts and a full Python interpreter, which search for data in cryptocurrency wallet browser extensions while establishing persistence on the affected systems. Notably, the qq-console package is attributed to a known North Korean campaign named “Contagious Interview.”

Researchers identified another package, helmet-validate, published on August 23 2024, which employs a different attack method. It inserts JavaScript code that retrieves and executes malicious code from a remote endpoint, ipcheck[.]cloud. This domain is linked to previous North Korean operations, including fake job campaigns using the mirotalk[.]net domain, highlighting a pattern of recurring tactics.

The most recent package, sass-notification, was published on August 27 2024, and is linked to the “Moonstone Sleet” campaign. This package uses obfuscated JavaScript to run scripts that download, decrypt and execute remote payloads while removing traces of malicious activity, leaving behind what appears to be harmless software.

Read more on North Korean cyber-threats: North Korean Hackers Spoofing Journalist Emails to Spy on Policy Experts

Increasing Exploitation of npm By Threat Actors

Phylum warned these attacks underscore the increasing exploitation of npm by threat actors to compromise developer systems. 

See also  Hackers turn Facebook ads into crypto draining traps

“The diversity and simultaneous deployment of these attack vectors reveal a coordinated and relentless campaign by North Korean-aligned threat actors,” the company said.

“These adversaries continuously exploit the inherent trust in the npm ecosystem to compromise developers, infiltrate companies and steal cryptocurrency or any other assets that could lead to illicit financial gains.”

Source link

attacks hackers Korean Launch North npm Package wave

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

Value Locked in Defi Surpasses $40 Billion, Marking a Significant Recovery

October 27, 2023

WIF Price Prediction: Critical $0.20 Break Determines Next 15% Move

May 28, 2026

Are NFTs Going to Make a Comeback in 2026? Market Outlook & Future Trends

February 7, 2026

Type above and press Enter to search. Press Esc to cancel.