15 Jun 2025

North Korean Hackers Infiltrate GitHub & NPM to Steal Crypto

Watercolor-style illustration of a megaphone with a 'News' sign above it, set against a soft blue and orange abstract background - The Coinomist

Lazarus Group, a North Korean hacking unit responsible for numerous cyber attacks, has launched a new campaign targeting software developers and crypto wallets.

On this page

Cybersecurity researchers from STRIKE’s SecurityScorecard found that hackers are using advanced methods in their latest tactics.

Dubbed Operation Marstech Mayhem, the campaign introduces malware embedded in open-source GitHub repositories and npm (Node Package Manager) packages.

This attack differs from previous ones because it uses stealthy techniques that make detection significantly harder.

How the Attack Works

Developers are the main targets of Lazarus's operations. The attack works as follows: First, attackers create fake repositories containing malicious code, then promote them on social media platforms like Discord and GitHub.

When a victim clones and runs the repository, the malware executes in the background, giving attackers access to the system for further exploitation.

During the investigation, STRIKE confirmed that 233 victims were affected across the U.S., Europe, and Asia. Researchers warn that this number is expected to grow due to the widespread use of open-source packages.

The Marstech implant, which researchers believe first appeared in December 2024, has been linked to the GitHub profile “Success Friend”, which STRIKE suspects belongs to the Lazarus threat group. 

Crypto and Blockchain in the Focus of Lazarus Group

STRIKE identified an account linked to the attack, which listed web development skills and blockchain learning in its bio – a pattern consistent with Lazarus Group tactics.

The “SuccessFriend” profile was created in July 2024 and initially contributed legitimate code to gain credibility. However, in November 2024, the profile started publishing repositories connected to the recent operation.

STRIKE’s analysis showed that the group targets crypto wallets, including MetaMask, Exodus, and Atomic, across Linux, macOS, and Windows operating systems. The implant scans the system to find crypto wallets, read file contents, and extract metadata.

It targets wallet directories, extracts private keys, and sends them to the C2 server. Additionally, the implant can modify browser configuration files to inject stealthy payloads that can intercept transactions.

– they explain.

The malware collects and extracts data to steal sensitive information from the targeted folder. It contains anti-analysis code and techniques that make it difficult for analysts to understand and debug the malware.

Related: North Korean Hackers — Not So Great at Trading After All?

The Crypto Sector Needs to Stay Alert

In 2024, hackers stole $2.2 billion across 303 crypto breaches, with North Korean groups behind several major attacks. Governments and organizations are stepping up their efforts to fight back. In December 2024, South Korea hit individuals and companies linked to crypto theft with sanctions.

Research from STRIKE shows that hackers are constantly changing their tactics. They’re exploiting GitHub, posting fake job listings, and using all sorts of tricks to spread malware.

To stay safe, make sure to follow security best practices, stay updated on cyber threats, and double-check open-source code before using it.

Watch out for random messages pushing you to use certain packages – social engineering is a go-to trick for hackers. Keep an eye on your network activity too, since unusual outbound traffic could mean someone’s stealing your data.

Related: WhiteBIT Freezes $150M in Stolen Crypto: Here’s How

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
APS Drops €3M on Tokenized Real Estate in Italy—First-Ever Blockchain Deal

APS Drops €3M on Tokenized Real Estate in Italy—First-Ever Blockchain Deal

With €12B in assets under management, APS just closed its first tokenization deal, snapping up fractional shares of two Italian real estate assets via blockchain.

Anton Kryshtal
Demand for Circle Shares Pushes IPO Valuation to $6.9B

Demand for Circle Shares Pushes IPO Valuation to $6.9B

USDC stablecoin issuer Circle Internet Group launches its IPO on the NYSE, increasing the offering to 34 million shares at $31 each and raising around $1.1 billion.

Dmytro Psevdonimenko
Morning Digest: Key News on Ethereum Foundation, JPMorgan & the Fed

Morning Digest: Key News on Ethereum Foundation, JPMorgan & the Fed

JPMorgan weighs Bitcoin ETF-backed lending, Ethereum Foundation updates treasury strategy, Michelle Bowman appointed as Fed overseer. Details in the article.

Dmytro Psevdonimenko
Pakistan to Launch Bitcoin Reserve Using 2,000 MW of Excess Power

Pakistan to Launch Bitcoin Reserve Using 2,000 MW of Excess Power

Islamabad eyes a national Bitcoin reserve powered by 2,000 MW of surplus electricity—framing crypto as a hedge against inflation and macroeconomic volatility.

Anton Kryshtal
From Politics to Protocols: Decoding Eric Trump’s Unexpected Crypto Headlines

From Politics to Protocols: Decoding Eric Trump’s Unexpected Crypto Headlines

Politics continues to move into crypto, and Eric Trump’s involvement sparks debate. What drives his interest?

Daryna Nesterenko
Who Is Tomasz Stańczak? Inside the New Leadership of the Ethereum Foundation

Who Is Tomasz Stańczak? Inside the New Leadership of the Ethereum Foundation

Tomasz Stańczak is one of the co-executive directors at the Ethereum Foundation, contributing to strategic planning and operational oversight to support Ethereum’s long-term growth.

Anahit Avetisyan
Robert Kiyosaki and the Debt-Fueled Prophecy

Robert Kiyosaki and the Debt-Fueled Prophecy

Robert Kiyosaki says the end is here. With $1.2B in U.S. debt and a $1M Bitcoin prediction, the Rich Dad author is turning collapse into his ultimate performance.

Elina Moskovchuk
What Is a DDoS Attack in Crypto? A Guide to Defense in 2025

What Is a DDoS Attack in Crypto? A Guide to Defense in 2025

DDoS attacks remain one of the most serious threats to crypto infrastructure. They can disrupt websites, crypto exchanges, DeFi protocols, and blockchain nodes.

Daryna Nesterenko
Are Crypto IPOs Overhyped? A Closer Look at the Boom

Are Crypto IPOs Overhyped? A Closer Look at the Boom

Crypto IPOs are booming, driven by market optimism and clearer regulations. But are they a sign of industry maturity or just another wave of hype? We take a closer look.

Anahit Avetisyan
What Is Milady? Inside Ethereum’s Most Controversial NFT Cult 

What Is Milady? Inside Ethereum’s Most Controversial NFT Cult 

Milady is a prominent NFT collection often seen as social media profile pictures, but its complex story extends far beyond mere aesthetics.

Anahit Avetisyan
Strategic Bitcoin Reserve: What the U.S. Is Really Planning

Strategic Bitcoin Reserve: What the U.S. Is Really Planning

In March 2025, the U.S. officially announced a strategic Bitcoin reserve, becoming the first nation to incorporate a digital asset into its national reserve policy.

Vlad Vovk
What Is Aztec Network? 2025 Milestones and the Path to Mainnet

What Is Aztec Network? 2025 Milestones and the Path to Mainnet

Aztec is a privacy network on Ethereum, designed to allow developers to build privacy-focused decentralised applications without compromising transparency.

Anahit Avetisyan
zkEVM Explained: A New Way to Scale Ethereum Without Breaking It

zkEVM Explained: A New Way to Scale Ethereum Without Breaking It

Solving Ethereum’s congestion, zkEVM tech supports native bytecode and familiar dApps — but slashes gas fees, accelerates confirmation, and adds embedded privacy layers.

Vlad Vovk
Bitcoin Price Crashes to $103K After China Ban and Trump’s Threats Roil Markets

Bitcoin Price Crashes to $103K After China Ban and Trump’s Threats Roil Markets

A double blow from China’s crypto crackdown and Trump’s trade threats caused Bitcoin price to plunge to $103K, sparking concern among investors.

Anton Kryshtal
Bitcoin Price Falls to $105K as Traders React to Tariff Confusion and Volatility

Bitcoin Price Falls to $105K as Traders React to Tariff Confusion and Volatility

With uncertainty clouding U.S. tariff rulings and speculative pressure mounting, Bitcoin price retreated to the $105,000 support mark.

Anton Kryshtal
MORE
Crypto Spam Attacks: How to Save Your Deposit and Your Nerves

Crypto Spam Attacks: How to Save Your Deposit and Your Nerves

Unexpected airdrops, shady tokens in your wallet, pushy Discord messages, and weird invites to NFT projects—let’s learn how to stay afloat in a stream of digital noise.

Iaroslava Kramarenko
Why Crypto Trading Isn’t Gambling (Even If It Feels That Way Sometimes)

Why Crypto Trading Isn’t Gambling (Even If It Feels That Way Sometimes)

Is crypto trading just digital gambling? At first glance, the line seems thin. But they’re worlds apart: one relies on analysis and strategy, the other on luck and addiction.

Iaroslava Kramarenko
MORE