Malicious crypto-theft package targets Web3 developers in North Korean operation
2025-06-12 • Aikido •
Aikido found the npm package web3-wrapper-ethers impersonating the legitimate ethers library while targeting Web3, blockchain, and cryptocurrency developers. The package copied ethers metadata and modified the Wallet constructor to exfiltrate private keys, first to a localhost test endpoint and later to an encrypted destination that decoded to the malformed URL hxxp:/74.119.194[.]244/fetch. Multiple versions were released in one day, showing development-stage changes such as adding node-fetch, removing comments, and stripping debug logging while leaving the broken URL in place. Aikido notes that the IP overlaps Trend Micro indicators for Void Dokkaebi/DPRK-aligned activity, making the package relevant to North Korean cryptocurrency theft tracking even though the exfiltration URL appeared nonfunctional.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ff47554247f2094dda55b84b7da6e6c9 | 2025-06-12 | 2025-06-12 |
| HASH | fd81fc4d8379f535510c1f064549472… | 2025-06-12 | 2025-06-12 |
| [email protected] | 2025-06-12 | 2025-06-12 | |
| IPv4 | 74.119.194.244 | 2025-06-12 | 2025-06-12 |