15 Mar 2025

light mode

North Korean Hackers Infiltrate GitHub & NPM to Steal Crypto

North Korean Hackers Infiltrate GitHub & NPM to Steal Crypto

Lazarus Group, a North Korean hacking unit responsible for numerous cyber attacks, has launched a new campaign targeting software developers and crypto wallets.

On this page

Cybersecurity researchers from STRIKE’s SecurityScorecard found that hackers are using advanced methods in their latest tactics.

Dubbed Operation Marstech Mayhem, the campaign introduces malware embedded in open-source GitHub repositories and npm (Node Package Manager) packages.

This attack differs from previous ones because it uses stealthy techniques that make detection significantly harder.

How the Attack Works

Developers are the main targets of Lazarus's operations. The attack works as follows: First, attackers create fake repositories containing malicious code, then promote them on social media platforms like Discord and GitHub.

When a victim clones and runs the repository, the malware executes in the background, giving attackers access to the system for further exploitation.

During the investigation, STRIKE confirmed that 233 victims were affected across the U.S., Europe, and Asia. Researchers warn that this number is expected to grow due to the widespread use of open-source packages.

The Marstech implant, which researchers believe first appeared in December 2024, has been linked to the GitHub profile “Success Friend”, which STRIKE suspects belongs to the Lazarus threat group. 

Crypto and Blockchain in the Focus of Lazarus Group

STRIKE identified an account linked to the attack, which listed web development skills and blockchain learning in its bio – a pattern consistent with Lazarus Group tactics.

The “SuccessFriend” profile was created in July 2024 and initially contributed legitimate code to gain credibility. However, in November 2024, the profile started publishing repositories connected to the recent operation.

STRIKE’s analysis showed that the group targets crypto wallets, including MetaMask, Exodus, and Atomic, across Linux, macOS, and Windows operating systems. The implant scans the system to find crypto wallets, read file contents, and extract metadata.

It targets wallet directories, extracts private keys, and sends them to the C2 server. Additionally, the implant can modify browser configuration files to inject stealthy payloads that can intercept transactions.

– they explain.

The malware collects and extracts data to steal sensitive information from the targeted folder. It contains anti-analysis code and techniques that make it difficult for analysts to understand and debug the malware.

Related: North Korean Hackers — Not So Great at Trading After All?

The Crypto Sector Needs to Stay Alert

In 2024, hackers stole $2.2 billion across 303 crypto breaches, with North Korean groups behind several major attacks. Governments and organizations are stepping up their efforts to fight back. In December 2024, South Korea hit individuals and companies linked to crypto theft with sanctions.

Research from STRIKE shows that hackers are constantly changing their tactics. They’re exploiting GitHub, posting fake job listings, and using all sorts of tricks to spread malware.

To stay safe, make sure to follow security best practices, stay updated on cyber threats, and double-check open-source code before using it.

Watch out for random messages pushing you to use certain packages – social engineering is a go-to trick for hackers. Keep an eye on your network activity too, since unusual outbound traffic could mean someone’s stealing your data.

Related: WhiteBIT Freezes $150M in Stolen Crypto: Here’s How

The content on The Coinomist is for informational purposes only and should not be interpreted as financial advice. While we strive to provide accurate and up-to-date information, we do not guarantee the accuracy, completeness, or reliability of any content. Neither we accept liability for any errors or omissions in the information provided or for any financial losses incurred as a result of relying on this information. Actions based on this content are at your own risk. Always do your own research and consult a professional. See our Terms, Privacy Policy, and Disclaimers for more details.

Articles by this author
Pump․fun Meme Coin Launches Collapsed To 0.82%

Pump․fun Meme Coin Launches Collapsed To 0.82%

The Pump․fun platform has recorded an unprecedented drop in the weekly graduation rate of meme coins – for the first time, it fell below 1%, reaching 0.82%.

Anton Kryshtal
Senate Banking Committee Passes Stablecoin Bill: What the Genius Act Means 

Senate Banking Committee Passes Stablecoin Bill: What the Genius Act Means 

The Senate Banking Committee has endorsed the Senate Stablecoin Bill GENIUS (Guiding and Establishing National Innovation for U.S. Stablecoins), which seeks to set up a clear regulatory framework for payment of stablecoins.

Anahit Avetisyan
$100 Billion Gone! Bitcoin Speculators Trapped by the Market

$100 Billion Gone! Bitcoin Speculators Trapped by the Market

CryptoQuant reports that short-term Bitcoin investors lost over $100 billion while trying to cash in on BTC’s extreme volatility.

Anton Kryshtal
Crypto Scam Exposed: AML Bitcoin CEO Faces Conviction

Crypto Scam Exposed: AML Bitcoin CEO Faces Conviction

AML Bitcoin CEO Rowland Marcus Andrade was found guilty of wire fraud and money laundering by a federal jury in California after a five-week trial for misleading investors.

Anahit Avetisyan
How the Ethereum Foundation Is Shaping the Future of Crypto

How the Ethereum Foundation Is Shaping the Future of Crypto

For over a decade, the Ethereum Foundation has been the driving force behind Ethereum’s growth—from Vitalik Buterin’s white paper to a global financial and technological revolution.

Ivan Dikalenko
The Biggest Tweets in Crypto This Week: SEC vs Ripple Updates & More

The Biggest Tweets in Crypto This Week: SEC vs Ripple Updates & More

Summing up this week in Crypto Twitter/X: major announcements, updates, rumors, and interesting takes on the SEC vs Ripple case, Ethereum’s updates, the Trump family deal with Binance, and more.

Anahit Avetisyan
The Stablecoin Showdown: How USDC and Tether Compete for Dominance

The Stablecoin Showdown: How USDC and Tether Compete for Dominance

Two giants lead the stablecoin market—Tether (USDT) and USD Coin (USDC). But beneath their promise of stability lies a fierce competition.

Ivan Dikalenko
What Is Fiat Currency and Its Role in the Crypto World?

What Is Fiat Currency and Its Role in the Crypto World?

Discover fiat currency—a government-issued money without intrinsic value—and learn how it interacts with cryptocurrencies and influences digital financial systems worldwide.

The Coinomist
How to Short Crypto Safely and Effectively: Tips and Strategies

How to Short Crypto Safely and Effectively: Tips and Strategies

Learn advanced strategies for shorting crypto safely. This guide covers key tips, risk management techniques, and various methods like direct shorting, futures, margin trading, and options.

The Coinomist
Risk Reversal: A Deep Dive into Best Practices

Risk Reversal: A Deep Dive into Best Practices

Explore risk reversal strategies and learn best practices for managing risks in trading and business. Understand how to balance risk and reward to optimize outcomes.

The Coinomist
World Bridge Currency: Is XRP the Future of World Bridge Currencies?

World Bridge Currency: Is XRP the Future of World Bridge Currencies?

Explore XRP as a potential world bridge currency. Learn how its speed, low fees, and scalability could transform global cross-border transactions and reshape financial systems.

The Coinomist
What Is TRC20? Exploring the Tron Network Standard

What Is TRC20? Exploring the Tron Network Standard

Discover TRC20, the token standard on the TRON blockchain. Learn how TRC20 tokens work, their advantages like low fees and speed, and their use cases in DeFi, gaming, and more.

The Coinomist
What Is a Bullish Market? How to Spot One Before It Happens

What Is a Bullish Market? How to Spot One Before It Happens

Learn what a bullish market is, its key characteristics, and how to identify early signs before a full bull market develops. Gain insights into market trends and strategies.

The Coinomist
Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

Trump’s “US Crypto Reserve” Plan: A Game Changer or Just Talk?

It takes just one post from Trump to stir the crypto market. Recently, he announced on Truth Social that the evaluation of a strategic crypto reserve is in progress as part of his broader Trump crypto policy.

Anahit Avetisyan
Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

Trump’s Crypto Tax Plan: Smart Policy or Risky Gamble?

There’s been a lot of talk about possible changes to crypto tax policies in the U.S. One of the more controversial ideas floating around is “Trump no tax on crypto.” As Trump adopts a more crypto-friendly stance, major rumors have surfaced that he’s considering a 0% tax on crypto gains.

Anahit Avetisyan
MORE
Wealth, Influence, and Bitcoin: The Market Moves of the Ultra-Rich

Wealth, Influence, and Bitcoin: The Market Moves of the Ultra-Rich

Billionaires have a significant impact on digital asset prices, often driving instability and engaging in crypto market manipulation. This view is echoed by American entrepreneur David Wolfe.

The Coinomist
The New Crypto Sports Economy: Sponsorships, Fan Tokens, and NFTs 

The New Crypto Sports Economy: Sponsorships, Fan Tokens, and NFTs 

Crypto companies are shaking up crypto sport, partnering with clubs and stadiums for high-profile sponsorships. This means big bucks for athletes, thanks to advertising and fan tokens.

The Coinomist
MORE