Malicious crypto-theft package targets Web3 developers in North Korean operation

2025-06-12 Aikido

https://www.aikido.dev/blog/malicious-package-web3

Thumbnail for Malicious crypto-theft package targets Web3 developers in North Korean operation

Aikido found the npm package web3-wrapper-ethers impersonating the legitimate ethers library while targeting Web3, blockchain, and cryptocurrency developers. The package copied ethers metadata and modified the Wallet constructor to exfiltrate private keys, first to a localhost test endpoint and later to an encrypted destination that decoded to the malformed URL hxxp:/74.119.194[.]244/fetch. Multiple versions were released in one day, showing development-stage changes such as adding node-fetch, removing comments, and stripping debug logging while leaving the broken URL in place. Aikido notes that the IP overlaps Trend Micro indicators for Void Dokkaebi/DPRK-aligned activity, making the package relevant to North Korean cryptocurrency theft tracking even though the exfiltration URL appeared nonfunctional.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ff47554247f2094dda55b84b7da6e6c9 2025-06-12 2025-06-12
HASH fd81fc4d8379f535510c1f064549472… 2025-06-12 2025-06-12
EMAIL [email protected] 2025-06-12 2025-06-12
IPv4 74.119.194.244 2025-06-12 2025-06-12

Related Reports

« Back