Bitcoin
Bitcoin (BTC)
$65,932.00 0.36169
Bitcoin price
Ethereum
Ethereum (ETH)
$1,773.84 -0.12083
Ethereum price
XRP
XRP (XRP)
$1.22 0.39551
XRP price
BNB
BNB (BNB)
$605.39 0.16922
BNB price
Solana
Solana (SOL)
$73.98 1.02397
Solana price
Hyperliquid
Hyperliquid (HYPE)
$75.92 1.72937
Hyperliquid price
Cardano
Cardano (ADA)
$0.171359 -1.18345
Cardano price
Chainlink
Chainlink (LINK)
$8.30 1.518
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.078288 1.36644
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.67 0.24742
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000948 -18.3891
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$65,932.00 0.36169
Bitcoin price
Ethereum
Ethereum (ETH)
$1,773.84 -0.12083
Ethereum price
XRP
XRP (XRP)
$1.22 0.39551
XRP price
BNB
BNB (BNB)
$605.39 0.16922
BNB price
Solana
Solana (SOL)
$73.98 1.02397
Solana price
Hyperliquid
Hyperliquid (HYPE)
$75.92 1.72937
Hyperliquid price
Cardano
Cardano (ADA)
$0.171359 -1.18345
Cardano price
Chainlink
Chainlink (LINK)
$8.30 1.518
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.078288 1.36644
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.67 0.24742
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000948 -18.3891
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$65,932.00 0.36169
Bitcoin price
Ethereum
Ethereum (ETH)
$1,773.84 -0.12083
Ethereum price
XRP
XRP (XRP)
$1.22 0.39551
XRP price
BNB
BNB (BNB)
$605.39 0.16922
BNB price
Solana
Solana (SOL)
$73.98 1.02397
Solana price
Hyperliquid
Hyperliquid (HYPE)
$75.92 1.72937
Hyperliquid price
Cardano
Cardano (ADA)
$0.171359 -1.18345
Cardano price
Chainlink
Chainlink (LINK)
$8.30 1.518
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.078288 1.36644
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.67 0.24742
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000948 -18.3891
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$65,932.00 0.36169
Bitcoin price
Ethereum
Ethereum (ETH)
$1,773.84 -0.12083
Ethereum price
XRP
XRP (XRP)
$1.22 0.39551
XRP price
BNB
BNB (BNB)
$605.39 0.16922
BNB price
Solana
Solana (SOL)
$73.98 1.02397
Solana price
Hyperliquid
Hyperliquid (HYPE)
$75.92 1.72937
Hyperliquid price
Cardano
Cardano (ADA)
$0.171359 -1.18345
Cardano price
Chainlink
Chainlink (LINK)
$8.30 1.518
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.078288 1.36644
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.67 0.24742
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.0000948 -18.3891
Asteroid Shiba price

Lazarus infects hundreds software developers, targeting Solana and Exodus crypto wallets

Dorian Batycka
Edited by
News
Lazarus infects hundreds software developers, targeting Solana and Exodus crypto wallets

A new Lazarus campaign is spreading through npm packages, using BeaverTail malware to steal credentials, exfiltrate cryptocurrency data, and deploy a persistent backdoor.

North Korea‘s Lazarus Group has planted six malicious packages in npm, targeting developers and cryptocurrency users, a new research done the Socket Research Team reveals.

According to their findings, the malicious these packages, downloaded over 300 times, are designed to steal login credentials, deploy backdoors, and extract sensitive data from Solana-related cryptocurrency wallets or Exodus. The malware specifically targets browser profiles, scanning files from Chrome, Brave, and Firefox, as well as keychain data on macOS.

The identified packages — is-buffer-validator, yoojae-validator, event-handle-package, array-empty-validator, react-event-dependency, and auth-validator — use typosquatting, tricking developers with misspelled names into installing them.

“The stolen data is then exfiltrated to a hardcoded C2 server at hxxp://172.86.84[.]38:1224/uploads, following Lazarus’s well-documented strategy of harvesting and transmitting compromised information.”

Kirill Boychenko, threat intelligence analyst at Socket Security

Lazarus has previously used supply chain attacks through npm, GitHub, and PyPI to infiltrate networks, contributing to major hacks like the $1.5 billion Bybit exchange heist. The group’s tactics align with past campaigns leveraging multi-stage payloads to maintain long-term access, the cybersecurity experts note.

In late February, North Korean hackers targeted Bybit, one of the largest cryptocurrency exchanges, stealing around $1.46 billion worth of crypto in a highly sophisticated heist. The attack was reportedly carried out by compromising the computer of an employee at Safe, Bybit’s technology provider. Less than two weeks after the breach, Bybit’s CEO Ben Zhou stated that around 20% of the stolen funds had become untraceable, due to the hackers’ use of mixing services.