DPRK IT Worker-Related Account Takeover

2025-06-18 Ketman

https://www.ketman.org/dprk-it-worker-related-account-takeover.html

Thumbnail for DPRK IT Worker-Related Account Takeover

Ketman identifies a suspected DPRK IT worker-related GitHub account, AhegaoXXX, with privileged control over the Keeper-Wallet organization tied to Waves Protocol. After nearly two years of inactivity, the account pushed dependency updates, could create repositories and branches, and could trigger npm releases. A suspicious Keeper-Wallet-Extension change attempted to exfiltrate wallet logs and errors to an external database, which Ketman assesses could expose wallet keys or mnemonics. The report also points to likely compromise of Maxim Smolyakov’s GitHub/npm identity and possible web3tech.ru-linked maintainer account exposure, underscoring supply-chain risk from stale privileged developer accounts.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-06-18 2025-06-18
EMAIL [email protected] 2025-06-18 2025-06-18
URL https://web3tech.ru/ 2025-06-18 2025-06-18
URL https://www.npmjs.com/~msmolyak… 2025-06-18 2025-06-18
DOMAIN web3tech.ru 2025-06-18 2025-06-18

Related Reports

« Back