logo

Malicious crypto-theft package targets Web3 developers in North Korean operation

ID: 44a3defc-d3cc-534c-b5aa-1ba888487507

STIX ID: report--44a3defc-d3cc-534c-b5aa-1ba888487507

Feed Name: Aikido Security's Blog

Threat Score
70/100

Date Published: 2025-06-12

Date Updated: 2026-07-24

...
...

Aikido Security flagged a malicious npm package, 'web3-wrapper-ethers', that impersonates the legitimate ethers library and contains obfuscated code in its wallet constructor to exfiltrate private keys to an external IP (74.119.194.244). The package author, rapid releases, added node-fetch and modified wallet source to POST private keys; later versions obfuscated the target URL but a formatting bug rendered it non-functional. The report links the infrastructure to the actor 'Void Dokkaebi' and provides the package name and IP as IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.