lastweek.lazarus.day

LW39: Bitget theft, poisoned repositories, and blockchain command channels

Executive Summary

Last week’s reporting centered on a $387.5 million theft from Bitget and another round of developer-focused malware. Elliptic assessed the exchange attack as highly likely to be DPRK-linked after tracing laundering infrastructure shared with earlier thefts. Elsewhere, PolinRider kept reinfecting GitHub repositories through compromised developer machines, and Graphalgo moved into Terraform providers and Go modules.

Public blockchains played several roles across these operations. PolinRider and the XCTDH campaign used Ethereum transactions to distribute current command-server addresses, while Graphalgo used an Ethereum smart contract for encrypted, bidirectional tasking. Reporting on a DPRK IT-worker cell and a Konni espionage campaign also documented the people and tradecraft behind job fraud, malicious shortcuts, and modular PowerShell execution.

1. PolinRider reinfected repositories faster than developers could clean them

OpenSourceMalware reconstructed eight months of activity across three Binary-Mindz repositories and recovered 853 force-pushes. Developers removed the malware at least three times, but an infected contributor machine restored it, sometimes under the same commit message as the cleanup. The repositories carried several execution paths at once: automatic VS Code tasks, JavaScript disguised as Font Awesome files, code appended to eslint.config.mjs, and a loader in prisma.config.ts.1

Atlassian reported hundreds of malicious repositories and accounts tied to Contagious Interview. The company attributed the campaign with high confidence to North Korean threat actors and found repositories that combined obfuscated JavaScript, npm scripts, VS Code tasks, Git hooks, fake fonts, and SVG files to launch BeaverTail. Some victims became unwitting distributors after recruiters asked them to upload completed coding assessments from legitimate accounts.2

SlowMist traced another PolinRider chain through development branches of the Packagist package visanduma/nova-two-factor. A loader hidden after 507 spaces in tailwind.config.js decoded command-server addresses from Ethereum transaction recipients, then fetched Node.js and Python stages over plaintext HTTP. The final stealer targeted browser sessions, wallets, password managers, operating-system credential stores, and developer secrets.34

The operators also ran different loader variants in parallel. One build used an Ethereum wallet to recover its current command server and sent a build marker in the Sec-V request header. Another used a legitimate Font Awesome filename and heavier obfuscation. A separate investigation found the same pattern in a Web3 and fintech repository that had remained compromised for about ten months: a folder-open task ran an embedded WOFF2 file with Node.js, and the recovered loader queried Ethereum before fetching its next stage.15

The persistence mechanism sits outside any single branch or filename. Compromised credentials rewrote repository history, while infected workstations reintroduced malicious files after a revert. Useful evidence includes bursts of force-pushes across branches, committed folderOpen tasks, executable text inside font files, and unusual entries such as temp_auto_push.bat in .gitignore.1

2. Blockchain channels separated discovery, delivery, and tasking

Ransom-ISAC found that the DPRK-attributed XCTDH campaign had added an always-on Ethereum channel for command-server recovery. A signaling wallet sent 2,655 transactions over roughly 90 days. The first six bytes of each fabricated recipient address encoded an IPv4 address and port, allowing malware to find /boot infrastructure without storing the current endpoint in the sample. The channel ran alongside the campaign’s TRON, Aptos, and BSC delivery chain and supported DEV#POPPER.js and the OmniStealer credential harvester.6

Graphalgo used a different design in malicious Terraform providers and Go modules. Its Go RAT collected host data through Slack, then received encrypted commands through Slack or an Ethereum smart contract on the Arbitrum Sepolia testnet. The samples shared infrastructure and cryptographic material with earlier Graphalgo npm payloads. Aikido counted 18 unique hostnames in plaintext check-ins and assessed the operation as small and targeted.7

The Terraform providers activated only when two input values produced a specific SHA-256 hash, and one Go module required a particular price value. That conditional execution limited accidental exposure while placing the payload on DevOps workstations likely to hold cloud and deployment credentials. Fake Go ecosystem sites and forged Git commits supplied a plausible history for the packages.7

3. The Bitget theft pushed tracked DPRK-linked losses above $1 billion

Bitget reported unauthorized transfers from hot-wallet infrastructure on September 24. Its chief executive said the affected assets spanned Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, while cold wallets and the separately operated Bitget Wallet remained unaffected. She said IP behavior and on-chain analysis were highly consistent with known North Korean methods.8

A later Bitget update raised the confirmed loss to about $387.5 million after adding transfers on Zcash and TRON. The exchange said it had identified and remediated the vulnerability, contained further transfers, and engaged Mandiant and SlowMist. It also offered a 5% bounty for voluntary actions that froze or recovered affected funds.9

Elliptic assessed the attack as highly likely to be DPRK-linked. It cited connections between the stolen assets and laundering infrastructure used after previous DPRK-attributed exploits, rapid conversion into native chain assets, off-chain indicators, and Bitget’s own assessment. Elliptic said the incident took its tracked total for DPRK-linked cryptocurrency theft in 2026 above $1 billion.10

4. IT-worker cells split interviews, development, and identity production

Hayden McKenzie documented a DPRK-affiliated cell that assigned spoken-English callers to interviews while other operatives performed the technical work. The cell maintained separate Slack workspaces for internal coordination and client-facing activity. One shared workbook staged about 1,200 female identities and held stolen personal and banking data for three real U.S. women. Operators used ixBrowser and proxies to isolate personas, while ChatGPT produced employment histories, biographies, and interview scripts.11

McKenzie assessed with high confidence that MageHire acted as the cell’s U.S. front and that its chief executive knowingly facilitated placements. The report describes the executive managing client relationships, authentication, and damage control after a caller failed an interview. Nine active operatives were listed in Shenyang and Dalian, with the broader cell using female callers, fabricated profiles, local endpoints, and developers working behind the visible applicant.11

5. Konni paired Ukraine-themed shortcuts with a modular PowerShell runner

SOCRadar attributed Operation Conflict Compass to Konni with moderate confidence. The campaign used LNK files disguised as PDFs and trojanized Zoom installers against Ukraine-focused targets. Lures covered Russia-Ukraine peace proposals, food prices, and a social-researcher resume. Execution created a scheduled task that ran every minute and launched VelvetCake, a lightweight PowerShell component that retrieved server-side modules.12

Recovered modules profiled hosts and security products, captured screenshots, and staged data for exfiltration. SOCRadar based its assessment on targeting, payload characteristics, URL patterns, shared infrastructure, and operator activity aligned with UTC+9 working hours.12

Security Alliance’s weekly incident data recorded 1.7 BTC and 14.2 ETH in DPRK-related losses, including a fake Microsoft Teams invitation. It also warned that operators were reactivating access established six to twelve months earlier and published new infrastructure associated with Contagious Interview, SINT-01, Konni, and UNC1069.13

What to Watch

Repository cleanup should begin with contributor endpoints, not a revert alone. Review every branch for force-push bursts, automatic VS Code tasks, executable configuration files, and text masquerading as fonts. Any host that ran the affected Graphalgo providers or modules should be reimaged, with source-control, package-publishing, cloud, and SSH credentials rotated from a clean system.

Network monitoring should connect public blockchain RPC calls with later requests to raw IP addresses, Slack API traffic from unexpected developer processes, and Node.js execution of non-JavaScript files. Cryptocurrency services should retain off-chain authentication and wallet-infrastructure telemetry alongside transaction tracing. Hiring teams should correlate the person on camera with endpoint location, account history, payment ownership, and the developer who later performs the work.

Reports Reviewed