• Dapps:16.23K
  • Blockchains:78
  • Active users:66.47M
  • 30d volume:$303.26B
  • 30d transactions:$879.24M

Lazarus Launches New Attack: Malicious npm Packages Target Credential and Crypto Data

user avatar

by Giorgi Kostiuk

4 hours ago


The Lazarus Group, known for its cyberattacks, is using new malicious npm packages to steal user credentials and cryptocurrency data.

Attack Targets and Methods Used

The campaign was uncovered by the Socket Research Team. Attackers utilize BeaverTail malware to infiltrate developers’ systems. Six malicious packages, including is-buffer-validator and yoojae-validator, were downloaded over 300 times before detection. These packages mimic legitimate libraries and once installed, scan browser profiles from Chrome, Brave, and Firefox to harvest credentials and crypto wallet data.

Threat History and Previous Attacks

Lazarus has a history of exploiting supply chain vulnerabilities, previously compromising npm, GitHub, and PyPI. They are known for leveraging multi-stage payloads to infiltrate systems and maintain access over time. Recently, they were linked to the $1.46 billion hack of the Bybit exchange.

Recent Heist at Bybit Exchange

The attack on Bybit exchange, one of the largest in crypto history, involved a compromised computer at the technology provider Safe. About 20% of the stolen funds became untraceable due to the use of crypto-mixing services. Bybit CEO Ben Zhou reported that the majority of funds remain traceable but recovery is complicated.

Lazarus attacks highlight the need for heightened vigilance and improved security measures to prevent compromise of user data and cryptocurrency assets.

0

Share

Other news

Kaspa Completes Transition to 10 Blocks Per Second to Accelerate Network

Kaspa completes its transition to 10 blocks per second, strengthening its PoW blockchain position.

user avatarGiorgi Kostiuk

a few seconds ago

iAssets by Injective: A New Era in Tokenizing Real-World Assets

Injective's iAssets are programmable financial instruments for efficient tokenization of real-world assets.

user avatarGiorgi Kostiuk

a minute ago

Pi Day: How the Project Has Evolved Since 2019

The evolution of Pi Network since 2019: from mobile mining to an open network.

user avatarGiorgi Kostiuk

2 minutes ago

HB230 Bill: A New Leap in Utah's Blockchain Initiatives

Utah advances blockchain innovation with HB230, but without Bitcoin reserves.

user avatarGiorgi Kostiuk

2 minutes ago

Sui Network and World Liberty Financial: New Partnership

Sui Network joins forces with WLFI to support Web3 projects by including $SUI in the strategic reserve.

user avatarGiorgi Kostiuk

3 minutes ago

Opportunities for Success with BNB Chain's Programs

BNB Chain provides comprehensive support programs for developers and startups in the blockchain world.

user avatarGiorgi Kostiuk

4 minutes ago

dapp expert logo
© 2020-2025. DappExpert. All rights reserved.
© 2020-2025. DappExpert. All rights reserved.

Important disclaimer: The information presented on the Dapp.Expert portal is intended solely for informational purposes and does not constitute an investment recommendation or a guide to action in the field of cryptocurrencies. The Dapp.Expert team is not responsible for any potential losses or missed profits associated with the use of materials published on the site. Before making investment decisions in cryptocurrencies, we recommend consulting a qualified financial advisor.