North Korea has changed tack: its latest campaign targets the NPM registry and owners of Exodus and Atomic cryptocurrency wallets. Carrying out a financially motivated string of attacks isn't the news here – North Korea's primary objective has long been to siphon money from enemy economies. The fresh finding is a JavaScript implant that hides itself in GitHub repositories and node package manager (NPM) packages typically used by crypto devs. According to SecurityScorecard's research, 233 individual victims have been confirmed thus far after installing the new Marstech1 implant, many features of which demonstrate North Korea's evolving tradecraft. Asked for more details about the victims, the vendor said it had none. Given Web3 developers' reliance on NPM and Marstech1's ability to evade detection using static and dynamic analyses, SecurityScorecard said the campaign presented a real danger to cryptocurrency developers. A supply chain risk exists since the compromised software packages could be downloaded and unwittingly introduced into applications, potentially compromising many more users. Marstech1 uses command and control (C2) infrastructure that communicates over port 3000 rather than 1224 or 1245, and lacks features of previous Lazarus campaigns such as the React web panel as seen in the recent Phantom Circuit attack. Lazarus is a cybercrime group allegedly run by the North Korean government. Marstech1's capabilities primarily involve targeting cryptocurrency wallets acr...
North Korea targets crypto developers via NPM supply chain attack
The Register
·Connor Jones
·Published Feb 13, 2025
·Updated
Affected Software
3 affected components
npm registry
Exodus Cryptocurrency Wallet
Atomic Cryptocurrency Wallet
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses North Korea's campaign targeting cryptocurrency developers through supply chain attacks on the NPM registry and specific wallet applications.
2
What security threats are associated with the NPM registry mentioned in the article?
The article highlights that North Korea is exploiting the NPM registry to launch attacks against crypto developers, posing significant security risks.
3
Which cryptocurrency wallets are specifically mentioned as being targeted?
The Exodus and Atomic cryptocurrency wallets are specifically mentioned as targets in the article.
4
What motivations are driving North Korea’s attacks on crypto developers?
The attacks are financially motivated, as North Korea seeks to exploit vulnerabilities in the crypto ecosystem.
5
How does the attack on the NPM registry affect the overall security of cryptocurrency projects?
The attack undermines the security framework of cryptocurrency projects by compromising trusted development channels.