Sunday, November 16, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

by DigestWire member
June 19, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

The post North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post
Megabill debt warnings fall on deaf ears inside the GOP

Megabill debt warnings fall on deaf ears inside the GOP

Coinbase Gives Platforms 24/7 USDC Settlements—Faster, Cheaper, Borderless

Coinbase Gives Platforms 24/7 USDC Settlements—Faster, Cheaper, Borderless

SOL price rally to $200 brewing, but 3 key catalysts must happen first

SOL price rally to $200 brewing, but 3 key catalysts must happen first

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Blackrock’s BUIDL Enters Binance Ecosystem With Expanding Onchain Institutional Reach

Shubman Gill under observation, out of remainder of Eden Gardens Test

Vermont beats UMaine hockey 2-1 to deny Black Bears sweep

Temperatures could fall to -7C as cold snap follows Storm Claudia

Pope Leo meets with film stars and directors at Vatican

Sherlock star’s ‘very odd’ new role opposite seven-foot bird in portrait of male grief

Trending

Devine three-for takes Scorchers past Strikers in rain-hit game
Cricket

Devine three-for takes Scorchers past Strikers in rain-hit game

by DigestWire member
November 16, 2025
0

Scorchers were 55 for 2, nine runs clear of the DLS target, when rain ended their chase...

Glen Powell Brings His UPS Driver to Crash ‘SNL’ Monologue: ‘He Thought It Was a Scam, But He Still Came’

Glen Powell Brings His UPS Driver to Crash ‘SNL’ Monologue: ‘He Thought It Was a Scam, But He Still Came’

November 16, 2025
XRP ETF Price Crash Explained

XRP ETF Price Crash Explained

November 16, 2025
Blackrock’s BUIDL Enters Binance Ecosystem With Expanding Onchain Institutional Reach

Blackrock’s BUIDL Enters Binance Ecosystem With Expanding Onchain Institutional Reach

November 16, 2025
Shubman Gill under observation, out of remainder of Eden Gardens Test

Shubman Gill under observation, out of remainder of Eden Gardens Test

November 16, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Devine three-for takes Scorchers past Strikers in rain-hit game November 16, 2025
  • Glen Powell Brings His UPS Driver to Crash ‘SNL’ Monologue: ‘He Thought It Was a Scam, But He Still Came’ November 16, 2025
  • XRP ETF Price Crash Explained November 16, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.