• bitcoinBitcoin (BTC) $ 74,214.00
  • ethereumEthereum (ETH) $ 2,267.47
  • tetherTether (USDT) $ 1.00
  • xrpXRP (XRP) $ 1.40
  • bnbBNB (BNB) $ 617.86
  • usd-coinUSDC (USDC) $ 0.999782
  • solanaSolana (SOL) $ 83.85
  • tronTRON (TRX) $ 0.332029
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • dogecoinDogecoin (DOGE) $ 0.093891
  • whitebitWhiteBIT Coin (WBT) $ 53.80
  • usdsUSDS (USDS) $ 0.999886
  • hyperliquidHyperliquid (HYPE) $ 40.93
  • leo-tokenLEO Token (LEO) $ 10.19
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • cardanoCardano (ADA) $ 0.243933
  • bitcoin-cashBitcoin Cash (BCH) $ 436.91
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • chainlinkChainlink (LINK) $ 9.11
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • moneroMonero (XMR) $ 348.89
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • memecoreMemeCore (M) $ 3.46
  • canton-networkCanton (CC) $ 0.149520
  • stellarStellar (XLM) $ 0.167161
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • ethena-usdeEthena USDe (USDE) $ 0.999603
  • zcashZcash (ZEC) $ 306.05
  • susdssUSDS (SUSDS) $ 1.08
  • daiDai (DAI) $ 0.999612
  • usd1-wlfiUSD1 (USD1) $ 0.999951
  • litecoinLitecoin (LTC) $ 54.61
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • paypal-usdPayPal USD (PYUSD) $ 0.999764
  • avalanche-2Avalanche (AVAX) $ 9.07
  • hedera-hashgraphHedera (HBAR) $ 0.088264
  • wethWETH (WETH) $ 2,268.37
  • suiSui (SUI) $ 0.930275
  • rainRain (RAIN) $ 0.007554
  • shiba-inuShiba Inu (SHIB) $ 0.000006
  • usdt0USDT0 (USDT0) $ 0.998824
  • the-open-networkToncoin (TON) $ 1.29
  • crypto-com-chainCronos (CRO) $ 0.068965
  • hashnote-usycCircle USYC (USYC) $ 1.12
  • tether-goldTether Gold (XAUT) $ 4,763.74
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.077132
  • pax-goldPAX Gold (PAXG) $ 4,767.75
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • bittensorBittensor (TAO) $ 240.42
  • global-dollarGlobal Dollar (USDG) $ 0.999682
  • polkadotPolkadot (DOT) $ 1.25
  • uniswapUniswap (UNI) $ 3.24
  • mantleMantle (MNT) $ 0.608264
  • falcon-financeFalcon USD (USDF) $ 0.997951
  • skySky (SKY) $ 0.076868
  • pi-networkPi Network (PI) $ 0.171639
  • nearNEAR Protocol (NEAR) $ 1.35
  • okbOKB (OKB) $ 82.58
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • aster-2Aster (ASTER) $ 0.675245
  • htx-daoHTX DAO (HTX) $ 0.000002
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • pepePepe (PEPE) $ 0.000004
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.10
  • ripple-usdRipple USD (RLUSD) $ 0.999726
  • usddUSDD (USDD) $ 1.00
  • aaveAave (AAVE) $ 91.12
  • internet-computerInternet Computer (ICP) $ 2.42
  • bfusdBFUSD (BFUSD) $ 0.999800
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.13
  • bitget-tokenBitget Token (BGB) $ 1.88
  • ethereum-classicEthereum Classic (ETC) $ 8.32
  • ondo-financeOndo (ONDO) $ 0.250031
  • kucoin-sharesKuCoin (KCS) $ 8.42
  • gatechain-tokenGate (GT) $ 7.14
  • morphoMorpho (MORPHO) $ 1.92
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • quant-networkQuant (QNT) $ 72.71
  • pump-funPump.fun (PUMP) $ 0.001786
  • united-stablesUnited Stables (U) $ 1.00
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.23
  • ethenaEthena (ENA) $ 0.114010
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.088800
  • kaspaKaspa (KAS) $ 0.034108
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • algorandAlgorand (ALGO) $ 0.101510
  • render-tokenRender (RENDER) $ 1.73
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • cosmosCosmos Hub (ATOM) $ 1.78
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • nexoNEXO (NEXO) $ 0.886358
  • usdtbUSDtb (USDTB) $ 0.999590
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 11.05
  • worldcoin-wldWorldcoin (WLD) $ 0.259480
  • wbnbWrapped BNB (WBNB) $ 759.61
  • blockchain-capitalBlockchain Capital (BCAP) $ 82.76
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • arbitrumArbitrum (ARB) $ 0.124455
  • aptosAptos (APT) $ 0.914234
  • filecoinFilecoin (FIL) $ 0.909773
  • dexeDeXe (DEXE) $ 14.72
  • flare-networksFlare (FLR) $ 0.007989
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • official-trumpOfficial Trump (TRUMP) $ 2.83
  • justJUST (JST) $ 0.075180
  • hash-2Provenance Blockchain (HASH) $ 0.010826
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • beldexBeldex (BDX) $ 0.079510
  • midnight-3Midnight (NIGHT) $ 0.036321
  • ousgOUSG (OUSG) $ 114.95
  • vechainVeChain (VET) $ 0.006986
  • jupiter-exchange-solanaJupiter (JUP) $ 0.168471
  • xdce-crowd-saleXDC Network (XDC) $ 0.029693
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • yldsYLDS (YLDS) $ 0.999866
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • ghoGHO (GHO) $ 0.998729
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.51
  • stable-2​​Stable (STABLE) $ 0.025501
  • usual-usdUsual USD (USD0) $ 0.997989
  • clbtcclBTC (CLBTC) $ 76,920.00
  • bonkBonk (BONK) $ 0.000006
  • siren-2Siren (SIREN) $ 0.705738
  • true-usdTrueUSD (TUSD) $ 0.998468
  • a7a5A7A5 (A7A5) $ 0.012480
  • edgexedgeX (EDGE) $ 1.34
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.206328
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • adi-tokenADI (ADI) $ 4.32
  • chilizChiliz (CHZ) $ 0.042975
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.675607
  • tbtctBTC (TBTC) $ 70,942.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.007034
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • euro-coinEURC (EURC) $ 1.18
  • dashDash (DASH) $ 33.50
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.999063
  • blockstackStacks (STX) $ 0.220328
  • layerzeroLayerZero (ZRO) $ 1.61
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.03
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.407638
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • venice-tokenVenice Token (VVV) $ 8.73
  • tezosTezos (XTZ) $ 0.358950
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • usxUSX (USX) $ 0.999395
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • ether-fiEther.fi (ETHFI) $ 0.452559
  • cocaCOCA (COCA) $ 1.30
  • pieversePieverse (PIEVERSE) $ 1.56
  • sei-networkSei (SEI) $ 0.054539
  • kinesis-goldKinesis Gold (KAU) $ 153.76
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • hastra-primePRIME (PRIME) $ 1.03
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • monadMonad (MON) $ 0.029681
  • sun-tokenSun Token (SUN) $ 0.018202
  • decredDecred (DCR) $ 19.86
  • aerodrome-financeAerodrome Finance (AERO) $ 0.372379
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • celestiaCelestia (TIA) $ 0.377518
  • curve-dao-tokenCurve DAO (CRV) $ 0.223499
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • apenftAINFT (NFT) $ 0.00000034
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • injective-protocolInjective (INJ) $ 3.23
  • bittorrentBitTorrent (BTT) $ 0.00000033
  • gnosisGnosis (GNO) $ 119.61
  • bitcoin-svBitcoin SV (BSV) $ 15.44
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • conflux-tokenConflux (CFX) $ 0.058426
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • kinesis-silverKinesis Silver (KAG) $ 80.21
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • lido-daoLido DAO (LDO) $ 0.355842
  • flokiFLOKI (FLOKI) $ 0.000031
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • doublezeroDoubleZero (2Z) $ 0.084352
  • spx6900SPX6900 (SPX) $ 0.307956
  • usdaiUSDai (USDAI) $ 0.999670
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • jasmycoinJasmyCoin (JASMY) $ 0.005632
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • kaiaKaia (KAIA) $ 0.047607
  • fraxLegacy Frax Dollar (FRAX) $ 0.993388
  • crvusdcrvUSD (CRVUSD) $ 0.999510
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • ape-and-pepeApe and Pepe (APEPE) $ 0.000001
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 2,265.06
  • syrupMaple Finance (SYRUP) $ 0.227425

North Korean Hackers Deploy 26 Malicious npm Packages

0 3


A new supply-chain threat is putting developers on alert. Security researchers warn that North Korean hackers have uploaded 26 malicious packages to the npm registry. This aims to infect developer machines and steal sensitive data.

GoPlus 中文社区发推提醒,朝鲜黑客向 npm 注册表发布了一组 26 个恶意软件包,这些恶意软件包都附带一个安装脚本(install.js),该脚本会在软件包安装过程中自动执行,进而运行位于“vendor/scrypt-js/version.js”中的恶意代码,…

— 吴说区块链 (@wublockchain12) March 3, 2026

The warning, shared by the GoPlus community on March 3, links the campaign to the well-known “Famous Chollima” hacking group. According to the report, the packages hide a remote access trojan (RAT) that activates during installation. The incident shows growing risks in open-source ecosystems. Especially for Web3 and crypto developers.

Malicious Packages Hide in Plain Sight

Researchers say the attackers published 26 fake packages that mimic legitimate developer tools. Those are especially linting and utility libraries. Each package includes an install.js script that runs automatically when the package is installed. Once triggered, the script executes hidden code located in vendor/scrypt-js/version.js. This code quietly downloads a remote access trojan from a malicious URL.

Because npm installs often run automatically inside development environments. Many users may not notice the infection. Security analysts note this tactic is effective because it abuses normal developer workflows. In short, the malware arrives disguised as routine tooling.

What the Malware Can Do?

The embedded RAT gives attackers deep access to infected systems. According to the GoPlus alert, the malware can perform several dangerous actions. It can log keystrokes, steal clipboard data and collect browser credentials. It also scans systems using TruffleHog to find exposed secrets. In more serious cases, it attempts to steal Git repositories and SSH keys. For crypto developers, the risk is even higher. Stolen keys or credentials could lead directly to wallet breaches or project compromises. That is why security teams are treating this campaign as high severity.

Links to Famous Chollima Group

Investigators have tied the activity to the North Korean hacking operation known as Famous Chollima. It’s a group tracked by security firms since at least 2018. The group has a history of targeting developers, crypto projects and financial platforms.

Recent analysis suggests the campaign uses advanced obfuscation techniques. Some reports mention steganography methods that hide command and control data in seemingly harmless text. The malware infrastructure also appears distributed across multiple hosting services, making takedowns harder. This pattern fits previous North Korean operations. That focuses on long-term infiltration rather than quick attacks.

Developers Urged to Stay Alert

Security experts are urging developers to verify package sources before installing dependencies. Even small projects can become entry points for larger supply-chain breaches. GoPlus specifically warned users to avoid the flagged packages and review dependency trees carefully. Teams are also encouraged to enable lockfiles, audit tools and runtime monitoring.

The incident is another reminder that open source ecosystems remain a prime target for state linked hackers. As Web3 and crypto development grow, the stakes keep rising. For now, experts say basic hygiene, checking packages and limiting trust. It remains the best defense.



Source link

Leave A Reply

Your email address will not be published.