• Crypto Market
  • Crypto List
  • Converter
The cryptonews hub
  • Currency Prices
  • Top Gainers
  • Top Losers
  • Trending News
  • Crypto News
    • Bitcoin
    • Ethereum
    • NFT
    • Tech
  • Blockchain
  • Market
  • Crypto Events
Reading: North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
Share
The cryptonews hubThe cryptonews hub
Font ResizerAa
  • Trending News
  • Crypto News
  • Blockchain
  • Market
  • Crypto Events
  • Trending News
  • Crypto News
    • Bitcoin
    • NFT
    • Ethereum
    • Tech
  • Blockchain
  • Market
  • Quick Links
    • Crypto Converter
    • Crypto List
    • Crypto Market
    • Currency Prices
    • Crypto Events
    • Exchange
    • Top Gainers
    • Top Losers
Follow US

© 2026 The Crypto News Hub. Powered by Pantrade Blockchain

The cryptonews hub > Blog > Trending News > North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates
Trending News

North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

Crypto Team
Last updated: June 19, 2025 6:43 am
Crypto Team
Published: June 19, 2025
Share
wp header logo 660 North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

- Advertisement -

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

source

Sonic turns to US expansion after token drops more than 60% in a year
Crypto heists reach $2.1B so far in 2025 as state-backed hackers ramp up attacks
Shareholders push back against high pay for public Bitcoin miner execs after record equity grants
Spot BTC ETFs fail to sure up Bitcoin decline as outflow streak hits $1.9B
Crypto Blockchain News Of the Day – 14-Nov-2022
Share This Article
Facebook Email Copy Link Print
Share
Previous Article wp header logo 659 Has Bitcoin Topped Out? This Key Metric Suggests Otherwise Has Bitcoin Topped Out? This Key Metric Suggests Otherwise
Next Article wp header logo 661 Solana vs Litecoin? K33 Says One Altcoin ETF Could Soar While the Other Tanks Solana vs Litecoin? K33 Says One Altcoin ETF Could Soar While the Other Tanks
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

Follow US

Find US on Socials
FacebookLike
XFollow
InstagramFollow
Trending News
19 KinetFlow Launch Boosts Conflux Cross-Chain Capabilities
KinetFlow Launch Boosts Conflux Cross-Chain Capabilities
wp header logo 1923 How M2 money supply and the dollar REALLY move Bitcoin price – The truth influencers aren’t telling you
How M2 money supply and the dollar REALLY move Bitcoin price – The truth influencers aren’t telling you
wp header logo 1922 This $4.3M crypto home invasion shows how a single data leak can put anyone’s wallet — and safety — at risk
This $4.3M crypto home invasion shows how a single data leak can put anyone’s wallet — and safety — at risk
wp header logo 1918 Japan’s 20% crypto tax sets a new bar in Asia, pressuring Singapore and Hong Kong as retail costs fall
Japan’s 20% crypto tax sets a new bar in Asia, pressuring Singapore and Hong Kong as retail costs fall
wp header logo 1916 Did you know Bitcoin can stay alive without the internet?
Did you know Bitcoin can stay alive without the internet?
The cryptonews hub

The Cryptonews Hub brings breaking news on Bitcoin, Ethereum, Ripple, NFTs, DeFi, and blockchain. Get real-time prices, expert analysis, and earn free Bitcoin. Follow for top crypto updates!

Top Insight

Snoop Dogg NFT Collection Sells Out in 30 Minutes
December 31, 2025
Ethereum Quietly Sets Record Smart Contract Deployments
December 31, 2025

Top Categories

  • Trending News
  • Crypto News
  • Bitcoin
  • Ethereum
  • NFT
  • Tech
  • Blockchain
  • Market

Quick Links

  • Crypto Market
  • Crypto List
  • Converter
  • Currency Price
  • Crypto Events
  • Top Exchanges
  • Top Gainers
  • Top Losers

© 2026 The Crypto News Hub. Powered by Pantrade Blockchain

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?