• Press Releases
    • Submit a press release
    • Read All
  • Contact us
Advertise
Bitcoinist.com
No Result
View All Result
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
    • Price
      • Bitcoin Price
      • Ethereum Price
      • Binance Coin Price
      • Litecoin Price
  • Industry
    • Industry News
    • Press Releases
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • How to do Crypto Gambling
      • Crypto Casinos
        • Ethereum Casinos
        • Solana Casinos
        • LiteCoin Casinos
        • DogeCoin Casinos
        • Live Crypto Casinos
        • New Casinos
        • Instant Withdrawal Casinos
        • Cash App Casinos
        • No KYC Casinos
        • VPN Casinos
        • Offshore Casinos
          • Crypto Casinos IT
          • Crypto Casinos ES
            • All Guides
          • Crypto Casinos JP
          • Crypto Casinos SG
          • Crypto Casinos MY
          • Crypto Casinos KR
          • No GAMSTOP Casinos in UK
          • No Cruks Casinos NL
      • Crypto Betting
        • No ID sportsbooks
    • Play Crypto Games
      • Crypto Poker
      • Crypto Slots
      • Crypto Blackjack
      • Crypto Crash Gambling
        • Aviator Sites
      • Plinko
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
  • Events
  • Play Games
Breaking News: Ripple CTO Steps Down, Accepts New Offer – What You Need To Know
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
    • Price
      • Bitcoin Price
      • Ethereum Price
      • Binance Coin Price
      • Litecoin Price
  • Industry
    • Industry News
    • Press Releases
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • How to do Crypto Gambling
      • Crypto Casinos
        • Ethereum Casinos
        • Solana Casinos
        • LiteCoin Casinos
        • DogeCoin Casinos
        • Live Crypto Casinos
        • New Casinos
        • Instant Withdrawal Casinos
        • Cash App Casinos
        • No KYC Casinos
        • VPN Casinos
        • Offshore Casinos
          • Crypto Casinos IT
          • Crypto Casinos ES
            • All Guides
          • Crypto Casinos JP
          • Crypto Casinos SG
          • Crypto Casinos MY
          • Crypto Casinos KR
          • No GAMSTOP Casinos in UK
          • No Cruks Casinos NL
      • Crypto Betting
        • No ID sportsbooks
    • Play Crypto Games
      • Crypto Poker
      • Crypto Slots
      • Crypto Blackjack
      • Crypto Crash Gambling
        • Aviator Sites
      • Plinko
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
  • Events
  • Play Games
Bitcoinist.com
No Result
View All Result
Breaking News: Ripple CTO Steps Down, Accepts New Offer – What You Need To Know
New Malware Targets Crypto Coders Through “Coding Challenges” — Here’s How It Works

New Malware Targets Crypto Coders Through “Coding Challenges” —Here’s How It Works

Samuel Edyme
by Samuel Edyme
5 months ago
·
Posted in Crypto News
Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

A North Korea-linked hacking group has reportedly launched a targeted campaign against cryptocurrency developers using malicious Python projects disguised as coding assignments.

According to cybersecurity researchers at Palo Alto Networks’ Unit 42, the group (known as Slow Pisces) is deploying an advanced malware chain to gain unauthorized access to systems of high-value individuals within the crypto space.

In a recent assessment, Prashil Pattni, a security researcher with Unit 42, explained that the attackers approached developers on LinkedIn, posing as potential employers.

Related Reading: Bitcoin Core V29 Ends Battle Dating Back To Satoshi

These interactions often included offers of freelance coding tasks or full-time job opportunities. Victims were directed to download and execute what appeared to be standard coding challenges hosted on GitHub. However, embedded in these projects was malicious code designed to install malware on the target’s system.

Multi-Stage Attack Targets High-Value Victims

The infection chain begins with the execution of a trojanized Python project, which while posing as a cryptocurrency price viewer, establishes contact with a remote server to fetch a second-stage payload under specific conditions.

An illustration of how the hackers gain access to their victims.
An illustration of how the hackers gain access to their victims. | Source: The Hacker News

This includes IP filtering, geolocation, and request header checks, allowing the malware to activate only on selected machines. The campaign uses RN Loader to send system information to the server, followed by deployment of RN Stealer, a tool capable of extracting sensitive data including iCloud Keychain entries, SSH keys, and configuration files from Apple macOS devices.

Pattni noted that this approach allows the threat actors to evade detection while targeting individuals with privileged access. Pattni said:

Focusing on individuals contacted via LinkedIn, as opposed to broad phishing campaigns, allows the group to tightly control the later stages of the campaign and deliver payloads only to expected victims.

Unit 42 researchers found that the campaign bears similarities to earlier attacks, such as Operation Dream Job and Alluring Pisces, in which malware was distributed through employment-themed lures.

In this case, YAML deserialization and JavaScript templating tools like EJS are used to conceal code execution and obfuscate the payload delivery process.

Linked Campaigns and Operational Focus

Slow Pisces, also known under aliases such as Jade Sleet, TraderTraitor, and UNC4899, has been connected to several high-profile operations including the February 2025 Bybit exchange breach.

According to Andy Piazza, Senior Director of Threat Intelligence at Unit 42, the attackers likely felt no need to change their methodology due to the lack of widespread public reporting prior to that breach.

The attackers appear to focus on fewer but higher-value victims, primarily those with backend or DevOps roles who may have direct or indirect access to wallet infrastructure or exchange systems. Piazza explained.

The recurrence of developers being targeted and the use of npm or Python packages occurs as developers often have the access needed by threat actors to steal cryptocurrency.

Researchers say the attackers have continually improved operational security, updating GitHub repository behavior and controlling payload deployment. Payloads are often stored in memory only and executed only when necessary, making analysis difficult and prolonging the malware’s utility.

Related Reading: Crypto Winter Ahead? Coinbase Warns of Bearish Signals Across the Market

As campaigns like this evolve, Pattni emphasized the need for developers to remain vigilant, especially when approached with freelance or employment opportunities involving external code downloads.

The global crypto market cap valuation on TradingView
The global digital currency market cap valuation. | Source: TradingView.com

Featured image created with DALL-E, Chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.
ShareTweetShareShare

Sign Up for Our Newsletter!

For updates and exclusive offers enter your email.

I consent to my submitted data being collected and stored.
Samuel Edyme

Samuel Edyme

Follow

Edyme is a writer, a content writer that specialises in writing about the crypto realm. Asides Bitcoinist and NewsBTC, Edyme's writing has been featured in top sites such as Blockchain.News, CoinMonk, Blockchain Reporter, Bitcoin Insider among others.

Full Profile

Related Posts

crypto

Too Tough? Poland’s New Crypto Law Faces Pushback

3 hours ago
Whales Inject an Extra $329K+ Into Bitcoin Hyper Ahead of Uptober – The Next 1000x Crypto?

Whales Inject an Extra $329K+ Into Bitcoin Hyper Ahead of Uptober – The Next 1000x Crypto?

10 hours ago
Bitcoin Prepares for Another Surge as Whales Buy $329K Bitcoin Hyper in a Day.

Bitcoin Prepares for Another Surge as Whales Buy $329K Bitcoin Hyper in a Day

10 hours ago
Crypto

No License, No Problem? Wisconsin Bill Aims To Ease Crypto Rules

11 hours ago

Spot XRP And Dogecoin ETF Approval Odds Hit 100%, Says Bloomberg Expert

12 hours ago
Best Crypto Presales to Watch as Bitcoin Reclaims $114K Ahead of Uptober

Best Crypto Presales to Watch as Bitcoin Reclaims $114K Ahead of Uptober

12 hours ago

Premium Sponsors

Press Releases

  • 距離上線僅剩3周:Snorter代幣ICO融資突破 415...

    20 hours ago
  • 上線倒計時:僅剩25天可搶購 Snorter Bot 代幣

    5 days ago
  • 加密錢包掀起發幣熱潮 Best Wallet...

    7 days ago
  • Bitcoin Hyper

    ChatGPT предсказва следващата 1000x...

    1 week ago
  • Snorter надхвърли $4 милиона след...

    1 week ago

Bitcoin news portal providing breaking news, guides, price analysis about decentralized digital money & blockchain technology.

Bitcoin

  • News
  • Price
  • Businesses
  • Acceptance
  • Technology
  • Investment
  • Regulation
  • Reviews

Altcoins

  • News
  • Price
  • Ethereum
  • Ripple
  • Litecoin
  • EOS

Categories

  • Blockchain
  • Security
  • FinTech
  • Technology
  • Trending
  • Breaking News
  • Press Releases
  • How to

About Us

  • Advertise
  • Contact us
  • Editorial Policy
  • Privacy Policy
© 2025 Bitcoinist.com. All Rights Reserved.
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
    • Price
      • Bitcoin Price
      • Ethereum Price
      • Binance Coin Price
      • Litecoin Price
  • Industry
    • Industry News
    • Press Releases
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • How to do Crypto Gambling
      • Crypto Casinos
      • Crypto Betting
    • Play Crypto Games
      • Crypto Poker
      • Crypto Slots
      • Crypto Blackjack
      • Crypto Crash Gambling
      • Plinko
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
  • Events
  • Play Games
Advertise

© 2025 Bitcoinist. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy.