repositories – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 19 Jun 2025 00:41:01 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 repositories – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 North Korean dev hijacks dormant Waves repositories, slips credential-stealing code in wallet updates https://earlybirdsinvest.com/north-korean-dev-hijacks-dormant-waves-repositories-slips-credential-stealing-code-in-wallet-updates/ https://earlybirdsinvest.com/north-korean-dev-hijacks-dormant-waves-repositories-slips-credential-stealing-code-in-wallet-updates/#respond Thu, 19 Jun 2025 00:41:00 +0000 https://earlybirdsinvest.com/north-korean-dev-hijacks-dormant-waves-repositories-slips-credential-stealing-code-in-wallet-updates/

A North Korean developer gained elevated privileges inside Waves Protocol’s Keeper-Wallet codebase, according to a June 18 report by Ketman.

The report highlighted routine scans for Democratic People’s Republic of Korea (DPRK) activity on GitHub, which uncovered the account “AhegaoXXX” pushing updates to Keeper-Wallet. 

The wallet’s repositories showed no legitimate commits after August 2023, yet they received multiple dependency bumps beginning in May 2025. 

Repository analytics indicated that the user can open branches, create releases, and publish to the Node Package Manager (NPM) registry, giving the operator complete control over the organization.

The report then linked “AhegaoXXX” to contracting rings of DPRK IT workers, which had previously used freelance channels to infiltrate software projects.

The account’s reach extended beyond simple maintenance. Redirect rules inside the main Waves Protocol namespace now point to identical packages inside the newly active Keeper-Wallet namespace, suggesting an insider moved code from the core organization to the wallet project.

Suspicious code changes

The report also mentioned one commit inside “Keeper-Wallet/Keeper-Wallet-Extension” that adds a function exporting wallet logs and runtime errors to an external database. 

The modified routine captures mnemonic phrases and private keys before transmission, raising the likelihood of credential exfiltration. The branch remains unmerged, but its presence indicates an intent to include the code in a production release.

The NPM registry records reflect related activity. Versions of “@waves/provider-keeper,” “@waves/waves-transactions,” and four other packages suddenly advanced after two years of dormancy. 

Each publication lists “msmolyakov-waves” as a maintainer. GitHub history shows that the account belonged to former Waves engineer Maxim Smolyakov and exhibited no activity since 2023 until it approved a pull request from “AhegaoXXX” and triggered a new NPM release in under four minutes. 

The report assessed that the engineer’s credentials now fall under DPRK control, providing the attacker with a second trusted path to distribute malicious builds.

Supply-chain exposure and countermeasures

The shift from isolated freelancing to direct repository control marks what the report called an “unusual cross-over” between ordinary DPRK contract work and an overt hacking campaign.

Download counts for affected packages remain low, but any Waves user who installs or updates Keeper-Wallet risks importing code that forwards secret phrases to a hostile server.

The publication advised development teams to tighten supply-chain defenses, including audit contributor privileges, removing inactive members from GitHub organizations, tracking who can trigger package releases, and monitoring repository redirects across ecosystems such as npm and Docker. 

Lastly, the firm encouraged regular reviews of publisher e-mail domains to detect dormant accounts that could approve rogue updates.

]]>
https://earlybirdsinvest.com/north-korean-dev-hijacks-dormant-waves-repositories-slips-credential-stealing-code-in-wallet-updates/feed/ 0 42823
Hackers Use Fake GitHub Repositories to Steal Crypto in “GitVenom” Scam https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/ https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/#respond Mon, 03 Mar 2025 06:25:04 +0000 https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/

Kaspersky, a cybersecurity firm, reported that hackers are using fake GitHub repositories to steal cryptocurrency and login credentials.

Kaspersky’s investigation also revealed evidence that some of these repositories have been active for at least two years. The scam, known as “GitVenom“, appears to have a higher concentration of victims in Russia, Brazil, and Turkey, though it has been observed worldwide.

Kaspersky researcher Georgy Kucherin revealed in a February 24 report that these fraudulent repositories pretend to offer useful tools, such as a Telegram bot for managing Bitcoin
BTC


$93,039.77

wallets or an Instagram automation tool. However, instead of functioning as described, they install malware that grants attackers access to sensitive information.

What is Chainlink? LINK Explained Simply (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Hackers included detailed descriptions and instructional files, which Kaspersky suspects may have been generated with artificial intelligence (AI). They also manipulated project activity by continuously updating a timestamp file, which made it look like the repository was actively maintained.

Kaspersky found that the advertised features were non-functional, and the files executed meaningless actions while running hidden malware in the background. Once installed, the malware extracted saved credentials, browsing history, and cryptocurrency wallet details, sending them to attackers through Telegram.

Another malicious component worked as a clipboard hijacker, which monitored copied wallet addresses and replaced them with the hacker’s own. This method allowed attackers to intercept cryptocurrency transactions without the victim noticing.

On February 5, Kaspersky researchers discovered malware hidden in app development tools used to create apps for Google Play and the Apple App Store. What damage could it cause? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/feed/ 0 22964
Malicious GitHub repositories deploying hidden attacks on crypto wallets https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/ https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/#respond Wed, 26 Feb 2025 12:14:12 +0000 https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/

Kaspersky researchers have identified an attack vector on GitHub that uses repositories to distribute code that targets crypto wallets.

The investigation revealed a campaign dubbed GitVenom, in which threat actors created hundreds of GitHub repositories purporting to offer utilities for social media automation, wallet management, and even gaming enhancements.

Although these repositories were designed to resemble legitimate open-source projects, their code failed to deliver the advertised functions. Instead, it embedded instructions to install cryptographic libraries, download additional payloads, and execute hidden scripts.

GitVenom repos

The malicious code appears across Python, JavaScript, C, C++, and C# projects. In Python-based repositories, a lengthy sequence of tab characters precedes commands that install packages like cryptography and fernet, ultimately decrypting and running an encrypted payload.

JavaScript projects incorporate a function that decodes a Base64-encoded script, triggering the malicious routine.

Similarly, in projects using C, C++, and C#, a concealed batch script within Visual Studio project files activates at build time. Per Kaspersky’s report, each payload is configured to fetch further components from an attacker-controlled GitHub repository.

These additional components include a Node.js stealer that collects saved credentials, digital wallet data, and browsing history before packaging the information into an archive for exfiltration via Telegram.

Open-source tools such as the AsyncRAT implant and the Quasar backdoor are also used to facilitate remote access. A clipboard hijacker that scans for crypto wallet addresses and replaces them with those controlled by the attackers is also used. 

Attack vector is not new

The campaign, which has been active for several years with some repositories originating two years ago, has triggered infection attempts worldwide. Telemetry data indicate that attempts linked to GitVenom have been most prominent in Russia, Brazil, and Turkey.

Kaspersky researchers stressed the importance of scrutinizing third-party code before execution, noting that open-source platforms, while essential to collaborative development, can also serve as conduits for malware when repositories are manipulated to mimic authentic projects.

Developers are advised to double-check the contents and activity of GitHub repositories before integrating code into their projects.

The report outlines that these projects use AI to artificially inflate commit histories and craft detailed README files. Thus, when reviewing a new repo, developers should check for overly verbose language, formulaic structure, and even leftover AI instructions or responses in these areas.

While using AI to help craft a README file is not a red flag in itself, identifying it should spur developers to investigate further before using the code. Looking for community engagement, reviews, and other projects using the repo may aid with this. However, fake AI-generated reviews and social media posts also make this a tough challenge.

Blocscale
]]>
https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/feed/ 0 21983