Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnAISquareMore
North Korean hacker group uses malicious npm packages to steal crypto wallet credentials

North Korean hacker group uses malicious npm packages to steal crypto wallet credentials

AiCoinAiCoin2026/05/01 00:15
Show original
According to Cryptopolitan, ReversingLabs has discovered that the North Korean hacker group Famous Chollima used a malicious npm package named PromptMink to compromise the open-source crypto trading project openpaw-graveyard by submitting code generated by Anthropic's Claude Opus AI model. This allowed them to steal users' crypto wallet credentials and system keys. Since September 2025, the group has been continuously distributing malicious npm packages, employing a two-layer strategy: first releasing “decoy” packages without malicious code, then carrying out attacks through a second-layer package. After the second-layer package is taken down, replacement versions are quickly published.
0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Santander Bank: Japan GPIF does not need to adjust asset allocation policy, $62 billion may face sell-off

Analysts at Spain's Santander Bank stated that Japan’s Government Pension Investment Fund (GPIF) could potentially sell up to $62 billion worth of U.S. Treasury bonds without needing to formally adjust its asset allocation policy.

智通财经2026/09/12 01:16
Santander Bank: Japan GPIF does not need to adjust asset allocation policy, $62 billion may face sell-off