PANews reported on June 19 that according to Cryptoslate, a North Korean developer has obtained advanced permissions in the Keeper-Wallet code base of Waves Protocol. The account "AhegaoXXX" has pushedPANews reported on June 19 that according to Cryptoslate, a North Korean developer has obtained advanced permissions in the Keeper-Wallet code base of Waves Protocol. The account "AhegaoXXX" has pushed

North Korean developers hijack dormant Waves repository, plant credential-stealing code in wallet update

2025/06/19 17:05
1 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

PANews reported on June 19 that according to Cryptoslate, a North Korean developer has obtained advanced permissions in the Keeper-Wallet code base of Waves Protocol. The account "AhegaoXXX" has pushed updates to the dormant code base since May 2025. The account has been confirmed to be associated with North Korea's IT outsourcing organization. Code review found that a commit added the function of sending wallet logs and runtime errors to an external database, which may steal mnemonics and private keys. Although the branch has not been merged, the attacker has released six malicious NPM packages that have not been updated for a long time by controlling the account of former Waves engineer Maxim Smolyakov.

The security report pointed out that this incident shows that North Korean hackers have shifted from ordinary outsourcing infiltration to direct control of code bases. It is recommended that the development team strengthen supply chain protection, including auditing contributor permissions, cleaning dormant accounts, and monitoring repository redirection. Currently, the download volume of the affected software is low, but Waves users who update Keeper-Wallet are at risk of credential leakage.

Opportunità di mercato
Logo Waves
Valore Waves (WAVES)
$0.4052
$0.4052$0.4052
-0.90%
USD
Grafico dei prezzi in tempo reale di Waves (WAVES)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

$30,000 in PRL + 15,000 USDT

$30,000 in PRL + 15,000 USDT$30,000 in PRL + 15,000 USDT

Deposit & trade PRL to boost your rewards!