Tag: web3
5 articles

Jade Sleet Targets Indian IT Provider with FLATROOF and ROOFDECK Backdoors
North Korean-aligned threat actor Jade Sleet has launched a targeted attack on an Indian IT provider, using FLATROOF and ROOFDECK backdoors to gain long-term access to high-value targets by exploiting developer workflows and supply-chain tooling. The attack, detected as early as March 18, 2026, is part of a persistent campaign that highlights the group's evolving tactics.

Malicious Firefox Extensions Target Web3 Wallets
Beware of malicious Firefox extensions that have been targeting Web3 wallets as part of a large-scale campaign, with 40 confirmed malicious add-ons and 37 working together to steal your cryptocurrency. This coordinated threat, known as Offside Wallet Theft Factory, has been active since March 2026.

North Korean Hackers Expose Web3 Pros to Sophisticated ClickFake Scams
One in three employees have admitted to using company tech for personal gain, and North Korean hackers are exploiting this vulnerability with a clever recruitment scam that can give them access to corporate funds. The sophisticated scheme, attributed to the notorious Famous Chollima group, targets Web3 and cryptocurrency pros with fake job offers on popular platforms like LinkedIn and Telegram.
Crypto Wallets Expose Users to Cross-Site Tracking Risks
Researchers at KU Leuven have uncovered a concerning vulnerability in popular crypto wallets, finding that they can leak user data, allowing for cross-site tracking and linking of separate addresses. This issue affects around 35 million users of 85 widely-used browser-extension wallets.

AI-Assisted Code Targets Crypto Wallets via Malicious npm Dependency
Researchers have uncovered a sneaky malicious npm campaign, dubbed PromptMink, linked to North Korean hackers Famous Chollima, which targets crypto developers with fake utility packages that secretly steal sensitive info and funds. The campaign's clever tactics even involve an AI-assisted code commit to fly under the radar.