The post North Korean Malware Hits Ethereum and BSC Wallets: Details appeared on BitcoinEthereumNews.com. According to a recent report by cybersecurity firm Cisco Talos, hackers linked to North Korea delivered malicious JavaScript via a fake cryptocurrency application and an npm package. The malware, which has been dubbed “OtterCookie/BeaverTrail,” is capable of stealing keystrokes, clipboard content, screenshots, and browser wallets of the likes of Metamask.  Modus operandi  A potential victim is typically lured with a bogus job or freelance gig. The attacks install malware with the help of an obfuscated JavaScript payload and collect sensitive data. The stolen files then get uploaded to the attacker’s servers. Notably, the hackers use a crypto app as bait, so they are specifically targeting those users who already have crypto wallets on their computers.  Immediate actions Those who think that they were exposed to the attack should assume that their hot wallets were compromised.  Attackers typically steal extension files and passwords together with seed phrases to drain wallets.  One should immediately start moving funds and revoke token approvals for old wallets that were potentially hacked.  It would also be advisable to wipe and reinstall the operating system, given that such malware  In order not to fall victim to hackers in the first place, one should refrain from running code from untrusted sources. They can be run via containers or VMs. $2 billion worth of stolen crypto  Earlier this month, TechCrunch reported that North Korean hackers had already stolen roughly $2 billion worth of crypto this year. The report, which cites data from blockchain sleuth Elliptic, says that the total amount of crypto stolen by the “Hermit Kingdom” currently stands at $6 billion.  Source: https://u.today/north-korean-malware-hits-ethereum-and-bsc-wallets-detailsThe post North Korean Malware Hits Ethereum and BSC Wallets: Details appeared on BitcoinEthereumNews.com. According to a recent report by cybersecurity firm Cisco Talos, hackers linked to North Korea delivered malicious JavaScript via a fake cryptocurrency application and an npm package. The malware, which has been dubbed “OtterCookie/BeaverTrail,” is capable of stealing keystrokes, clipboard content, screenshots, and browser wallets of the likes of Metamask.  Modus operandi  A potential victim is typically lured with a bogus job or freelance gig. The attacks install malware with the help of an obfuscated JavaScript payload and collect sensitive data. The stolen files then get uploaded to the attacker’s servers. Notably, the hackers use a crypto app as bait, so they are specifically targeting those users who already have crypto wallets on their computers.  Immediate actions Those who think that they were exposed to the attack should assume that their hot wallets were compromised.  Attackers typically steal extension files and passwords together with seed phrases to drain wallets.  One should immediately start moving funds and revoke token approvals for old wallets that were potentially hacked.  It would also be advisable to wipe and reinstall the operating system, given that such malware  In order not to fall victim to hackers in the first place, one should refrain from running code from untrusted sources. They can be run via containers or VMs. $2 billion worth of stolen crypto  Earlier this month, TechCrunch reported that North Korean hackers had already stolen roughly $2 billion worth of crypto this year. The report, which cites data from blockchain sleuth Elliptic, says that the total amount of crypto stolen by the “Hermit Kingdom” currently stands at $6 billion.  Source: https://u.today/north-korean-malware-hits-ethereum-and-bsc-wallets-details

North Korean Malware Hits Ethereum and BSC Wallets: Details

According to a recent report by cybersecurity firm Cisco Talos, hackers linked to North Korea delivered malicious JavaScript via a fake cryptocurrency application and an npm package.

The malware, which has been dubbed “OtterCookie/BeaverTrail,” is capable of stealing keystrokes, clipboard content, screenshots, and browser wallets of the likes of Metamask. 

Modus operandi 

A potential victim is typically lured with a bogus job or freelance gig. The attacks install malware with the help of an obfuscated JavaScript payload and collect sensitive data. The stolen files then get uploaded to the attacker’s servers.

Notably, the hackers use a crypto app as bait, so they are specifically targeting those users who already have crypto wallets on their computers. 

Immediate actions

Those who think that they were exposed to the attack should assume that their hot wallets were compromised. 

Attackers typically steal extension files and passwords together with seed phrases to drain wallets. 

One should immediately start moving funds and revoke token approvals for old wallets that were potentially hacked. 

It would also be advisable to wipe and reinstall the operating system, given that such malware 

In order not to fall victim to hackers in the first place, one should refrain from running code from untrusted sources. They can be run via containers or VMs.

$2 billion worth of stolen crypto 

Earlier this month, TechCrunch reported that North Korean hackers had already stolen roughly $2 billion worth of crypto this year.

The report, which cites data from blockchain sleuth Elliptic, says that the total amount of crypto stolen by the “Hermit Kingdom” currently stands at $6 billion. 

Source: https://u.today/north-korean-malware-hits-ethereum-and-bsc-wallets-details

Market Opportunity
Octavia Logo
Octavia Price(VIA)
$0.001769
$0.001769$0.001769
-1.50%
USD
Octavia (VIA) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

CEO Sandeep Nailwal Shared Highlights About RWA on Polygon

The post CEO Sandeep Nailwal Shared Highlights About RWA on Polygon appeared on BitcoinEthereumNews.com. Polygon CEO Sandeep Nailwal highlighted Polygon’s lead in global bonds, Spiko US T-Bill, and Spiko Euro T-Bill. Polygon published an X post to share that its roadmap to GigaGas was still scaling. Sentiments around POL price were last seen to be bearish. Polygon CEO Sandeep Nailwal shared key pointers from the Dune and RWA.xyz report. These pertain to highlights about RWA on Polygon. Simultaneously, Polygon underlined its roadmap towards GigaGas. Sentiments around POL price were last seen fumbling under bearish emotions. Polygon CEO Sandeep Nailwal on Polygon RWA CEO Sandeep Nailwal highlighted three key points from the Dune and RWA.xyz report. The Chief Executive of Polygon maintained that Polygon PoS was hosting RWA TVL worth $1.13 billion across 269 assets plus 2,900 holders. Nailwal confirmed from the report that RWA was happening on Polygon. The Dune and https://t.co/W6WSFlHoQF report on RWA is out and it shows that RWA is happening on Polygon. Here are a few highlights: – Leading in Global Bonds: Polygon holds 62% share of tokenized global bonds (driven by Spiko’s euro MMF and Cashlink euro issues) – Spiko U.S.… — Sandeep | CEO, Polygon Foundation (※,※) (@sandeepnailwal) September 17, 2025 The X post published by Polygon CEO Sandeep Nailwal underlined that the ecosystem was leading in global bonds by holding a 62% share of tokenized global bonds. He further highlighted that Polygon was leading with Spiko US T-Bill at approximately 29% share of TVL along with Ethereum, adding that the ecosystem had more than 50% share in the number of holders. Finally, Sandeep highlighted from the report that there was a strong adoption for Spiko Euro T-Bill with 38% share of TVL. He added that 68% of returns were on Polygon across all the chains. Polygon Roadmap to GigaGas In a different update from Polygon, the community…
Share
BitcoinEthereumNews2025/09/18 01:10
Q4 2024 Growth Beats Expectations With 0.9% Surge

Q4 2024 Growth Beats Expectations With 0.9% Surge

The post Q4 2024 Growth Beats Expectations With 0.9% Surge appeared on BitcoinEthereumNews.com. New Zealand Retail Sales Soar: Q4 2024 Growth Beats Expectations
Share
BitcoinEthereumNews2026/02/23 07:03
Vitalik Buterin Explains How Crypto Can Protect Users When Perfect Security Remains Impossible

Vitalik Buterin Explains How Crypto Can Protect Users When Perfect Security Remains Impossible

Ethereum co-founder Vitalik Buterin has outlined a new framework for crypto security, offering practical strategies rooted in redundancy, multi-angle verification
Share
Coinstats2026/02/23 06:08