North Korean Developer Compromises Waves Protocol Wallet in Credential-Stealing Attack
A North Korean operative infiltrated the codebase of Waves Protocol's Keeper-Wallet, inserting malicious code to harvest sensitive user data. The attacker, operating under the GitHub alias "AhegaoXXX," gained elevated privileges to modify dependencies and redirect package namespaces—a clear sign of insider-level access.
Repository analytics show the wallet's repositories had lain dormant since August 2023 before suspicious activity resumed in May 2025. The compromised account could publish updates to NPM, create releases, and alter critical infrastructure. Forensic evidence ties the actor to DPRK IT contracting rings known for infiltrating software projects through freelance channels.
The most damning modification surfaces in the Keeper-Wallet-Extension commit logs: a function designed to exfiltrate wallet logs, runtime errors, and—most critically—mnemonic phrases and private keys to an external server. This breach underscores the growing sophistication of state-sponsored crypto attacks.