Skip to main content

Tag: web3

5 articles

Rows of computer workstations and servers in a brightly-lit Indian IT services office.

Jade Sleet Targets Indian IT Provider with FLATROOF and ROOFDECK Backdoors

North Korean-aligned threat actor Jade Sleet has launched a targeted attack on an Indian IT provider, using FLATROOF and ROOFDECK backdoors to gain long-term access to high-value targets by exploiting developer workflows and supply-chain tooling. The attack, detected as early as March 18, 2026, is part of a persistent campaign that highlights the group's evolving tactics.

Analyst 207
Person working at desk with Firefox browser open on laptop amidst papers and cryptocurrency notes.

Malicious Firefox Extensions Target Web3 Wallets

Beware of malicious Firefox extensions that have been targeting Web3 wallets as part of a large-scale campaign, with 40 confirmed malicious add-ons and 37 working together to steal your cryptocurrency. This coordinated threat, known as Offside Wallet Theft Factory, has been active since March 2026.

Analyst 207
Laptop and smartphone sit on a table in a brightly-lit office space surrounded by blurred people.

North Korean Hackers Expose Web3 Pros to Sophisticated ClickFake Scams

One in three employees have admitted to using company tech for personal gain, and North Korean hackers are exploiting this vulnerability with a clever recruitment scam that can give them access to corporate funds. The sophisticated scheme, attributed to the notorious Famous Chollima group, targets Web3 and cryptocurrency pros with fake job offers on popular platforms like LinkedIn and Telegram.

Analyst 207
Person sitting at desk with laptop and crypto wallet interface surrounded by multiple monitors in a university setting.

Crypto Wallets Expose Users to Cross-Site Tracking Risks

Researchers at KU Leuven have uncovered a concerning vulnerability in popular crypto wallets, finding that they can leak user data, allowing for cross-site tracking and linking of separate addresses. This issue affects around 35 million users of 85 widely-used browser-extension wallets.

Analyst 207
Cluttered coding workstation with lines of code on laptop screen and scattered notes.

AI-Assisted Code Targets Crypto Wallets via Malicious npm Dependency

Researchers have uncovered a sneaky malicious npm campaign, dubbed PromptMink, linked to North Korean hackers Famous Chollima, which targets crypto developers with fake utility packages that secretly steal sensitive info and funds. The campaign's clever tactics even involve an AI-assisted code commit to fly under the radar.

Analyst 207