CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

North Korea’s Lazarus Group Hacks Software Developers

March 12, 2025
in Crypto News
Reading Time: 3 mins read
A A
0
North Korea’s Lazarus Group Hacks Software Developers
0
SHARES
4
VIEWS
ShareShareShareShareShare
  • Lazarus Group is targeting Solana and Exodus wallet users.
  • The hacking group is responsible for the Bybit hack and related high-profile crypto thefts.

Lazarus Group, a group of hackers working for the North Korean government regime, is back in the news. This time, new research from Socket found the group had planted six malicious packages in npm, targeting software developers and cryptocurrency users.

Lazarus Group Linked to Software Attack

According to the report from Socket Research, the six malicious packages linked to Lazarus collectively were downloaded over 330 times. These packages were designed to steal login credentials, deploy backdoors, and extract sensitive data from Solana-related crypto wallets or Exodus.

The research pointed out that the techniques and tactics observed in this npm attack closely align with Lazarus’s known operations. In the recent attack, the malware specifically targets browser profiles, scanning files from Chrome, Brave, Firefox, and keychain data on macOS.

The six malicious packages are is-buffer-validator, yoojae-validator, event-handle-package, array-empty-validator, react-event-dependency, and auth-validator. The researchers claimed Lazarus used typosquatting, tricking developers with misspelled names into installing them. 

For instance, the is-buffer-validator closely resembles the widely used is-buffer module authored by Socket CEO Feross Aboukhadijeh. The legitimate is-buffer package has 33 million weekly downloads and over 134 million total downloads, highlighting its widespread adoption.

Additionally, Lazarus previously infiltrated networks using supply chain attacks via GitHub, PyPI, and npm. This has contributed to major hacks like the $1.4 billion Bybit exchange heist. As we covered in our latest report, Lazarus stole 401,346 ETH from Bybit, amounting to $1.4 billion. 

The hack stemmed from a masked transaction targeting the exchange’s Ethereum multisig cold wallet. Bybit’s CEO, Ben Zhou, explained that Bybit’s cold wallet executed a transfer to its hot wallet, which initially appeared legitimate. 

However, the attackers masked the transaction, displaying the correct address and a seemingly authentic @safe URL, deceiving all signers. Zhou said that around 20% of the stolen funds had become untraceable due to hackers’ use of mixing services.

Crypto Users Still Losing Money to Hacks

The recent Lazarus attack highlights the crypto sector’s increasing vulnerability, with even cybersecurity experts at risk from these complex schemes. 

In a recent study we reported on, the FBI said North Korean hackers are targeting the crypto industry with well-disguised social engineering attacks. The agency warned that bad players are focusing on employees of DeFi firms, especially those linked with spot Bitcoin ETF issuers. 

These events remind the market to change systems to more recent, safer versions. As outlined in our recent blog post, hackers exploited a vulnerability in Fusion v1’s outdated smart contract, draining over $5 million in assets.

Before this attack, law enforcement authorities in Thailand arrested four Russian nationals on suspicion of participating in a worldwide cyberattack using Phobos ransomware. Across the globe, almost 1,000 victims, including 17 Swiss businesses, are reported to have fallen victim to the scam. Collectively, they have lost around $16 million in Bitcoin (BTC).


Recommended for you:


Credit: Source link

RELATED POSTS

European Authorities Bust $815M Crypto Fraud Ring, Arrest Nine Across Border

Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala

Polish PM Claims Russia Influence Blocked Crypto Bill

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

Pi Network Tops Crypto Gainers with 20% Jump as Bitcoin Recovers and Best Wallet ICO Nears $11M

Next Post

Sony’s Soneium & LINE Partner to Bring Blockchain Mini-Apps to 200M Users

Related Posts

62 People Arrested in Turkey, Allegedly Connected to the Thodex Exchange Heist
Crypto News

European Authorities Bust $815M Crypto Fraud Ring, Arrest Nine Across Border

December 8, 2025
Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala
Crypto News

Bybit Institutional Sets the Stage for 2026 at High-Profile Abu Dhabi Gala

December 8, 2025
Polish PM Claims Russia Influence Blocked Crypto Bill
Crypto News

Polish PM Claims Russia Influence Blocked Crypto Bill

December 8, 2025
Next Post
Sony’s Soneium & LINE Partner to Bring Blockchain Mini-Apps to 200M Users

Sony’s Soneium & LINE Partner to Bring Blockchain Mini-Apps to 200M Users

Why BlackRock & Grayscale Should Consider a Shiba Inu ETF – 10 Key Reasons

Shiba Inu Enhances SHIB Metaverse with In-Game Fishing Economy

Recommended Stories

No Content Available

Popular Stories

  • BRICS Unites 40 Nations at Leaders’ Summit — Russia Pushes for Global Partnerships

    BRICS Unites 40 Nations at Leaders’ Summit — Russia Pushes for Global Partnerships

    0 shares
    Share 0 Tweet 0
  • Crypto Exchange Kraken Says Decentraland, The Sandbox and Metaverse Sector Far Outperforming Market Year-on-Year

    0 shares
    Share 0 Tweet 0
  • Bitfarms Adopts New Shareholder Rights Plan Amid Tribunal Decision

    0 shares
    Share 0 Tweet 0
  • ATOM Hits 2-Month High, as XRP Extends Recent Gains – Market Updates Bitcoin News

    0 shares
    Share 0 Tweet 0
  • Coinbase Rolls Out AI-Driven ERC-20 Scam Token Detection System

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • How crypto derivatives liquidation drove Bitcoin’s 2025 crash
  • Robinhood Charges Into Indonesia as Next Explosive Crypto Market
  • Exploring Chainlink’s Role Beyond Price Feeds in the Blockchain Ecosystem

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.