GoPlus: Beware of 26 malicious software packages released by North Korean hackers that can be remotely downloaded and execute Trojans

PANews March 3rd: The GoPlus Chinese community on X platform issued a warning that North Korean hackers have released a set of 26 malicious packages on the npm registry. These packages all include an installation script (“install.js”) that automatically executes during installation, running malicious code located in “vendor/scrypt-js/version.js”. The malicious code downloads and executes a remote access Trojan (RAT) via the same malicious URL, enabling keylogging, clipboard theft, browser credential collection, TruffleHog secret scanning of Git repositories, and SSH key theft. This incident is linked to a North Korean hacking group called “Famous Chollima.”

Users and developers are advised to verify the source and security of packages before installation to avoid these 26 malicious packages and prevent privacy leaks or asset loss:

argonist@0.41.0
bcryptance@6.5.2
bee-quarl@2.1.2
bubble-core@6.26.2
corstoken@2.14.7
daytonjs@1.11.20
ether-lint@5.9.4
expressjs-lint@5.3.2
fastify-lint@5.8.0
formmiderable@3.5.7
hapi-lint@19.1.2
iosysredis@5.13.2
jslint-config@10.22.2
jsnwebapptoken@8.40.2
kafkajs-lint@2.21.3
loadash-lint@4.17.24
mqttoken@5.40.2
prism-lint@7.4.2
promanage@6.0.21
sequelization@6.40.2
typoriem@0.4.17
undicy-lint@7.23.1
uuindex@13.1.0
vitetest-lint@4.1.21
windowston@3.19.2
zoddle@4.4.2

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

AI is making crypto's security problem even worse, Ledger CTO warns

Crypto platforms — and investors — have long suffered from hacker attacks and exploits. Now, artificial intelligence (AI) is making that threat even worse. That’s the view of Charles Guillemet, chief technology officer at crypto wallet provider Ledger, who said the economics of cybersecurity are

CoinDesk1m ago

Drift Protocol Stolen $285 Million: North Korean Hackers Prepared for 6 Months, Using Durable Nonce to Bypass Multi-Signatures

On April 1, the Drift Protocol on the Solana chain was attacked by hackers, resulting in losses of about $285 million and a sharp drop in TVL. The investigation found that the attackers carried out a social engineering infiltration lasting 6 months, using Durable Nonce to bypass multiple signatures, highlighting the threat that nation-state hackers pose to DeFi and raising questions about Circle’s response speed.

ChainNewsAbmedia1h ago

Drift says $270 million exploit was a six-month North Korean intelligence operation

A six-month intelligence operation preceded the $270 million exploit of Drift Protocol and was carried out by a North Korean state-affiliated group, according to a detailed incident update published by the team earlier on Sunday. The attackers first made contact around fall 2025 at a major crypto c

CoinDesk1h ago

A Gansu Tianshui Court Tries a Virtual Currency Money Laundering Case: The Defendant Who “Ran Errands to Withdraw Cash” Was Sentenced to Two Years and Four Months

A court in Qinzhou District, Tianshui City, Gansu Province, is trying a virtual-currency money-laundering case. The defendant used a part-time “high-paying errands” job to withdraw more than 390k yuan and, with knowledge of what was going on, exchange it for virtual currency, earning a profit of 21.5k yuan. The court sentenced him to two years and four months in prison and fined him. The judge reminded the public to stay alert to related activities in order to prevent them from fueling crime.

GateNews5h ago

Here's what 'cracking' bitcoin in 9 minutes by quantum computers actually means

Google's Quantum AI team said earlier this week that a future quantum computer could derive a bitcoin private key from a public key in roughly nine minutes. The number ricocheted across social media and spooked markets. But, what does it actually mean in practice? Let's start with how bitcoin

CoinDesk11h ago
Comment
0/400
No comments