Home » Crypto Crime » North Korea’s New Cyber Tactic: Weaponizing the Open-Source Supply Chain

North Korea’s New Cyber Tactic: Weaponizing the Open-Source Supply Chain

16.10.2025 15:00 2 min. read Alexander Zdravkov
SHARE: SHARES
North Korea’s New Cyber Tactic: Weaponizing the Open-Source Supply Chain

A new report by U.S. cybersecurity firm Socket has revealed that North Korean hackers have infiltrated one of the internet’s most vital open-source ecosystems, turning it into a weapon for cyber theft.

The attackers uploaded over 300 malicious code packages to npm, the world’s largest JavaScript software library used by millions of developers globally.

These corrupted packages appeared legitimate but secretly installed malware capable of stealing login credentials, browser data, and crypto wallet keys once downloaded. Socket traced the campaign – dubbed “Contagious Interview” – to North Korean state-sponsored groups that have long impersonated tech recruiters targeting developers in blockchain and Web3 sectors.

The implications are severe. Npm underpins much of today’s digital infrastructure, meaning a compromise can cascade across thousands of apps through standard software updates. Experts have repeatedly warned that supply-chain attacks like this are among the hardest to detect, as they exploit the trust developers place in widely used dependencies.

Socket’s researchers identified the malicious activity through fake package names mimicking popular libraries such as express, dotenv, and hardhat, along with code linked to known North Korean malware families like BeaverTail and InvisibleFerret. The malware operated entirely in memory, making it difficult to trace. By the time the attack was uncovered, the infected packages had already been downloaded roughly 50,000 times.

The hackers also relied on fake LinkedIn recruiter profiles – a familiar tactic in Pyongyang’s cyber playbook – to distribute their malware and gain access to systems containing crypto wallets or company credentials.

Although GitHub, which owns npm, has removed most of the identified threats and tightened account verification, cybersecurity analysts warn that new malicious uploads continue to appear. The open nature of npm, while fostering innovation, also creates opportunities for exploitation.

For developers, this incident is a stark reminder that every dependency download carries risk. Experts recommend scanning packages before installation, implementing automated monitoring tools, and assuming that any external code could potentially execute harmful scripts. In an ecosystem built on openness, vigilance has become the first line of defense.

Alexander has been working in the crypto industry for three years, during which time he has established himself through his active participation in monitoring market dynamics and technological innovations. His interest in cryptocurrencies and new technologies is not just a professional commitment, but a deep personal passion. He follows the news in the sector daily, analyzes trends, and is excited about every new step in the development of blockchain solutions. His enthusiasm drives him to continuously learn and share knowledge, as he sees the future in digital finance and its role in global transformation.

Telegram

SHARE: SHARES
More Crypto Crime News
Previous News CaretDown
North Korean Agent Exposed in Crypto Job Scam at Kraken

In a cybersecurity twist that sounds more like espionage fiction than reality, Kraken recently intercepted an attempted infiltration by a North Korean hacker—disguised as a job seeker.

North Korean Hackers Allegedly Linked to $305 Million Crypto Exchange Exploit

Recent developments suggest that the Lazarus Group, a notorious state-sponsored hacking entity, may be behind the $305 million breach of Japanese crypto exchange DMM Bitcoin.

North Korean Hackers May Target U.S. Bitcoin ETFs, Experts Warns

North Korean hackers could potentially shift their focus to U.S.-based Bitcoin exchange-traded funds (ETFs), according to security experts.

North Korean Hackers Shift to Phishing Campaigns Targeting Crypto Firms

North Korean hackers, under the BlueNoroff subgroup of the Lazarus Group, have escalated their cyberattacks, shifting from social media manipulation to targeted phishing emails in their 'Hidden Risk' campaign.

North Korean Hackers Steal Over $2 Billion in Crypto in 2025, Marking Record Year of Cyber Theft

North Korea-linked hacking groups have looted more than $2 billion in cryptocurrency so far in 2025, according to a new report from blockchain analytics firm Elliptic.

Northern Data Faces Legal Battle Over Financial Misrepresentation Allegations

Northern Data, a company with stakes in both cryptocurrency and AI infrastructure, is currently facing a lawsuit filed in California by former executives Joshua Porter and Gulsen Kama.

Norway Backs EU Crypto Regulations While Exploring Potential CBDC

Norway’s central bank, Norges Bank, has backed the EU’s Markets in Crypto-Assets Regulation (MiCA) as it considers a central bank digital currency (CBDC).

Norway Weighs Temporary Freeze on Crypto Mining to Conserve Energy

Norway may hit the pause button on cryptocurrency mining later this year. The government announced Friday it will study whether to impose a provisional ban on mining data centers, arguing that energy and grid capacity should be reserved for more pressing needs.

Norway’s Central Bank Set to Decide on CBDC Implementation Next Year

Next year, Norges Bank, Norway's central bank, will decide on the potential establishment of its own central bank digital currency (CBDC).

Norway’s $1.7T Wealth Fund Boosts Bitcoin Exposure by 83% in Q2

Norges Bank Investment Management (NBIM), the operator of Norway’s $1.7 trillion Government Pension Fund Global and the world’s largest sovereign wealth fund, has sharply increased its exposure to Bitcoin-linked assets, according to analysis of recent regulatory filings.

Norway’s Wealth Fund Expands Bitcoin Holdings Significantly

Norway’s sovereign wealth fund, NBIM, has increased its Bitcoin holdings to approximately $149.48 million, with a total of 2,446 BTC.

Norway’s Wealth Fund Quietly Becomes a Major Bitcoin Holder

Norway’s giant sovereign wealth fund - worth about $1.5 trillion — now holds more Bitcoin exposure than ever before, though not by directly buying the cryptocurrency.

Norwegian Mining Firm Adopts Bitcoin as Treasury Reserve

Oslo-based seabed-mining firm Green Minerals is shifting its treasury reserves from kroner and dollars into bitcoin, calling the move a hedge against inflation and geopolitical risk.

Notcoin Says Tap-to-Earn Games Are Over

Notcoin, one of the breakout names in Web3 gaming last year, says the days of mindless "tap-to-earn" mechanics are likely over.

Nubank Suspends Trading of Nucoin, Offers Conversion Options

Brazilian digital bank Nubank has announced the immediate suspension of trading for its native cryptocurrency, Nucoin.

Nvidia and Apple Eye Investment in OpenAI’s Next Funding Round

Nvidia and Apple are rumored to be interested in joining OpenAI's next funding round, which could potentially raise the company's valuation to over $100 billion.

Nvidia CEO Continues Massive Share Sell-Off Amid Market Shifts

Nvidia CEO Jensen Huang has recently sold $49 million worth of NVDA shares, continuing a significant divestment trend.

Nvidia CEO Dumps $104M in Shares Amid Stock Volatility

Nvidia's CEO Jensen Huang has been rapidly offloading his shares in the company amid recent stock fluctuations.

Nvidia CEO Urges UK to Invest in AI Infrastructure or Risk Falling Behind

During London Tech Week, Nvidia CEO Jensen Huang highlighted a critical gap in the UK’s artificial intelligence ambitions: while the country is home to exceptional talent, it lacks the computing backbone necessary to lead globally.

Nvidia Continues Losing Streak – AI Tokens Are Surging

AI-related cryptocurrencies saw significant growth last week, while Nvidia shares lost over $400 million in market capitalization.

No Comments yet!

Your Email address will not be published.