logo

Lazarus Lures Developers With Backdoored Coding Tests

ID: 970b3a19-a301-5b7b-a725-b76626abbff0

STIX ID: report--970b3a19-a301-5b7b-a725-b76626abbff0

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Mayura Kathir

...
...

### Executive summary: HexagonalRodent, a DPRK-linked subgroup, uses AI-assisted malware and backdoored take‑home coding challenges to compromise Web3 developers, exfiltrating seed phrases and wallet data at scale (26,584 wallets across 2,726 systems with up to $12M exposed) via NodeJS/Python toolkits (BeaverTail, OtterCookie, InvisibleFerret) and a compromised Open VSX extension; operators employ centralized C2/panel infrastructure and AI to automate and manage multi-team wallet theft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.