Home North Korea’s Lazarus Group spreads crypto-stealing malware through open-source software

North Korea’s Lazarus Group spreads crypto-stealing malware through open-source software

TLDR

  • North Korea’s Lazarus Group spreads crypto-stealing malware via GitHub and NPM packages.
  • The malware targets Exodus and Atomic wallets on Linux, macOS, and Windows.
  • Researchers confirmed 233 victims, urging developers to monitor supply chain security.

Researchers have reportedly discovered a highly advanced operation from North Korea that’s sneaking crypto-stealing malware into open-source software. The stealthy campaign is designed to spread malware, putting unsuspecting users at risk.

In a blog post published on Thursday (Feb. 13), STRIKE analysts from SecurityScorecard said that North Korea’s Lazarus Group was spreading “undetectable” malicious code through GitHub and NPM packages via Operation Marstech Mayhem. The team also added on X: “Developers are unknowingly pulling infected repositories into their projects, putting crypto wallets and software supply chains at risk.”

STRIKE found that the group had engineered an advanced implant, codenamed “marstech1.” They wrote: “This state-of-the-art tool marks a significant evolution from earlier iterations deployed in global campaigns against developers, featuring unique functional enhancements that distinctly set it apart.”

How does North Korea’s Lazarus Group target crypto developers?

According to cybersecurity researchers, the SuccessFriend GitHub profile linked to the infamous Lazarus Group has been injecting JavaScript implants into repositories, blending them with legitimate code. To make things even trickier, the profile has also committed harmless code, making it even harder to spot its hostile intent.

This JavaScript implant is specifically targeting Exodus and Atomic cryptocurrency wallets on Linux, macOS, and Windows. Once installed, the North Korean threat actor scans the system for crypto wallets, attempting to read file contents or extract metadata to steal sensitive information.

So far, STRIKE confirmed 233 victims have been affected across the US, Europe, and Asia. Cited by The Register, Ryan Sherstobitoff, SecurityScorecard’s SVP of threat research and intelligence, said: “The introduction of the Marstech1 implant, with its layered obfuscation techniques – from control flow flattening and dynamic variable renaming in JavaScript to multi-stage XOR decryption in Python – underscores the threat actor’s sophisticated approach to avoiding both static and dynamic analysis.”

ReadWrite has previously covered the group’s activities. In September, the FBI issued an advisory warning that North Korea has been aggressively targeting cryptocurrency businesses and companies, in a bid to potentially fund its national ambitions, including missile and nuclear weapons development.

Sherstobitoff stressed the importance of staying ahead of these threats, urging organizations and developers to take proactive security measures. He added that organizations needed to “continuously monitor supply chain activities, and integrate advanced threat intelligence solutions to mitigate the risk.”

Featured image: Canva

About ReadWrite’s Editorial Process

The ReadWrite Editorial policy involves closely monitoring the gambling and blockchain industries for major developments, new product and brand launches, game releases and other newsworthy events. Editors assign relevant stories to in-house staff writers with expertise in each particular topic area. Before publication, articles go through a rigorous round of editing for accuracy, clarity, and to ensure adherence to ReadWrite's style guidelines.

Suswati Basu
Tech journalist

Suswati Basu is a multilingual, award-winning editor and the founder of the intersectional literature channel, How To Be Books. She was shortlisted for the Guardian Mary Stott Prize and longlisted for the Guardian International Development Journalism Award. With 18 years of experience in the media industry, Suswati has held significant roles such as head of audience and deputy editor for NationalWorld news, digital editor for Channel 4 News and ITV News. She has also contributed to the Guardian and received training at the BBC As an audience, trends, and SEO specialist, she has participated in panel events alongside Google. Her…

Get the biggest iGaming headlines of the day delivered to your inbox

    By signing up, you agree to our Terms and Privacy Policy. Unsubscribe anytime.

    Gambling News

    Explore the latest in online gambling with our curated updates. We cut through the noise to deliver concise, relevant insights, keeping you informed about the ever-changing world of iGaming and its most important trends.

    In-Depth Strategy Guides

    Elevate your game with tailored strategies for sports betting, table games, slots, and poker. Learn how to maximize bonuses, refine your tactics, and boost your chances to beat the house.

    Unbiased Expert Reviews

    Honest and transparent reviews of sportsbooks, casinos and poker rooms crafted through industry expertise and in-depth analysis. Delve into intricacies, get the best bonus deals, and stay ahead with our trustworthy guides.