North Korean developers hijack dormant Waves repository, plant credential-stealing code in wallet update

2025/06/19 17:05

PANews reported on June 19 that according to Cryptoslate, a North Korean developer has obtained advanced permissions in the Keeper-Wallet code base of Waves Protocol. The account "AhegaoXXX" has pushed updates to the dormant code base since May 2025. The account has been confirmed to be associated with North Korea's IT outsourcing organization. Code review found that a commit added the function of sending wallet logs and runtime errors to an external database, which may steal mnemonics and private keys. Although the branch has not been merged, the attacker has released six malicious NPM packages that have not been updated for a long time by controlling the account of former Waves engineer Maxim Smolyakov.

The security report pointed out that this incident shows that North Korean hackers have shifted from ordinary outsourcing infiltration to direct control of code bases. It is recommended that the development team strengthen supply chain protection, including auditing contributor permissions, cleaning dormant accounts, and monitoring repository redirection. Currently, the download volume of the affected software is low, but Waves users who update Keeper-Wallet are at risk of credential leakage.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.