• Press Releases
    • Submit a press release
    • Read All
  • Contact us
Advertise
Bitcoinist.com
Join Lightchain AI
No Result
View All Result
👆 BUY LIGHTCHAIN HERE 👆
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
    • Price
      • Bitcoin Price
      • Ethereum Price
      • Binance Coin Price
      • Litecoin Price
  • Industry
    • Industry News
    • Press Releases
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • How to do Crypto Gambling
      • Crypto Casinos
        • Ethereum Casinos
        • Solana Casinos
        • LiteCoin Casinos
        • DogeCoin Casinos
        • Live Crypto Casinos
        • New Casinos
        • Instant Withdrawal Casinos
        • Cash App Casinos
        • No KYC Casinos
        • VPN Casinos
        • Offshore Casinos
          • Crypto Casinos IT
          • Crypto Casinos ES
            • All Guides
          • Crypto Casinos JP
          • Crypto Casinos SG
          • Crypto Casinos MY
          • Crypto Casinos KR
          • No GAMSTOP Casinos in UK
          • No Cruks Casinos NL
      • Crypto Betting
        • No ID sportsbooks
    • Play Crypto Games
      • Crypto Poker
      • Crypto Slots
      • Crypto Blackjack
      • Crypto Crash Gambling
        • Aviator Sites
      • Plinko
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
  • Events
  • Play Games
Breaking News: Ripple And SEC Reach Major Deal: Remaining $75M Penalty Returned, Injunction Lifted
👆 BUY LIGHTCHAIN HERE 👆
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
    • Price
      • Bitcoin Price
      • Ethereum Price
      • Binance Coin Price
      • Litecoin Price
  • Industry
    • Industry News
    • Press Releases
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • How to do Crypto Gambling
      • Crypto Casinos
        • Ethereum Casinos
        • Solana Casinos
        • LiteCoin Casinos
        • DogeCoin Casinos
        • Live Crypto Casinos
        • New Casinos
        • Instant Withdrawal Casinos
        • Cash App Casinos
        • No KYC Casinos
        • VPN Casinos
        • Offshore Casinos
          • Crypto Casinos IT
          • Crypto Casinos ES
            • All Guides
          • Crypto Casinos JP
          • Crypto Casinos SG
          • Crypto Casinos MY
          • Crypto Casinos KR
          • No GAMSTOP Casinos in UK
          • No Cruks Casinos NL
      • Crypto Betting
        • No ID sportsbooks
    • Play Crypto Games
      • Crypto Poker
      • Crypto Slots
      • Crypto Blackjack
      • Crypto Crash Gambling
        • Aviator Sites
      • Plinko
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
  • Events
  • Play Games
Bitcoinist.com
No Result
View All Result
Breaking News: Ripple And SEC Reach Major Deal: Remaining $75M Penalty Returned, Injunction Lifted
New Malware Targets Crypto Coders Through “Coding Challenges” — Here’s How It Works

New Malware Targets Crypto Coders Through “Coding Challenges” —Here’s How It Works

Samuel Edyme
by Samuel Edyme
4 weeks ago
·
Posted in Crypto News
Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

A North Korea-linked hacking group has reportedly launched a targeted campaign against cryptocurrency developers using malicious Python projects disguised as coding assignments.

According to cybersecurity researchers at Palo Alto Networks’ Unit 42, the group (known as Slow Pisces) is deploying an advanced malware chain to gain unauthorized access to systems of high-value individuals within the crypto space.

In a recent assessment, Prashil Pattni, a security researcher with Unit 42, explained that the attackers approached developers on LinkedIn, posing as potential employers.

Related Reading: Bitcoin Core V29 Ends Battle Dating Back To Satoshi

These interactions often included offers of freelance coding tasks or full-time job opportunities. Victims were directed to download and execute what appeared to be standard coding challenges hosted on GitHub. However, embedded in these projects was malicious code designed to install malware on the target’s system.

Multi-Stage Attack Targets High-Value Victims

The infection chain begins with the execution of a trojanized Python project, which while posing as a cryptocurrency price viewer, establishes contact with a remote server to fetch a second-stage payload under specific conditions.

An illustration of how the hackers gain access to their victims.
An illustration of how the hackers gain access to their victims. | Source: The Hacker News

This includes IP filtering, geolocation, and request header checks, allowing the malware to activate only on selected machines. The campaign uses RN Loader to send system information to the server, followed by deployment of RN Stealer, a tool capable of extracting sensitive data including iCloud Keychain entries, SSH keys, and configuration files from Apple macOS devices.

Pattni noted that this approach allows the threat actors to evade detection while targeting individuals with privileged access. Pattni said:

Focusing on individuals contacted via LinkedIn, as opposed to broad phishing campaigns, allows the group to tightly control the later stages of the campaign and deliver payloads only to expected victims.

Unit 42 researchers found that the campaign bears similarities to earlier attacks, such as Operation Dream Job and Alluring Pisces, in which malware was distributed through employment-themed lures.

In this case, YAML deserialization and JavaScript templating tools like EJS are used to conceal code execution and obfuscate the payload delivery process.

Linked Campaigns and Operational Focus

Slow Pisces, also known under aliases such as Jade Sleet, TraderTraitor, and UNC4899, has been connected to several high-profile operations including the February 2025 Bybit exchange breach.

According to Andy Piazza, Senior Director of Threat Intelligence at Unit 42, the attackers likely felt no need to change their methodology due to the lack of widespread public reporting prior to that breach.

The attackers appear to focus on fewer but higher-value victims, primarily those with backend or DevOps roles who may have direct or indirect access to wallet infrastructure or exchange systems. Piazza explained.

The recurrence of developers being targeted and the use of npm or Python packages occurs as developers often have the access needed by threat actors to steal cryptocurrency.

Researchers say the attackers have continually improved operational security, updating GitHub repository behavior and controlling payload deployment. Payloads are often stored in memory only and executed only when necessary, making analysis difficult and prolonging the malware’s utility.

Related Reading: Crypto Winter Ahead? Coinbase Warns of Bearish Signals Across the Market

As campaigns like this evolve, Pattni emphasized the need for developers to remain vigilant, especially when approached with freelance or employment opportunities involving external code downloads.

The global crypto market cap valuation on TradingView
The global digital currency market cap valuation. | Source: TradingView.com

Featured image created with DALL-E, Chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.
ShareTweetShareShare

Sign Up for Our Newsletter!

For updates and exclusive offers enter your email.

I consent to my submitted data being collected and stored.
Samuel Edyme

Samuel Edyme

Follow

Edyme is a writer, a content writer that specialises in writing about the crypto realm. Asides Bitcoinist and NewsBTC, Edyme's writing has been featured in top sites such as Blockchain.News, CoinMonk, Blockchain Reporter, Bitcoin Insider among others.

Full Profile

Related Posts

states

States Go Crypto: $632 Million In Strategy Stock Held Across 14 US Funds

13 hours ago
Crypto

Crypto Entrepreneurs In France Now Under Guard After Kidnapping Surge

19 hours ago
OpenAI Codex Hype Grows – Final Days to Grab Mind of Pepe ($MIND)

OpenAI Codex Hype Grows – Final Days to Grab Mind of Pepe ($MIND)

20 hours ago
Best Altcoins for Security in 2025: Lessons from Coinbase, Binance, and Kraken

Best Altcoins for Security in 2025: Lessons from Coinbase, Binance, and Kraken

21 hours ago
stablecoin, crypto

GENIUS Act To Advance? Stablecoin Legislation Will Face New Vote Next Week

24 hours ago
Abu Dhabi’s Crypto Bet Deepens with $408M Bitcoin ETF Position in BlackRock’s IBIT

Abu Dhabi’s Crypto Bet Deepens with $408M Bitcoin ETF Position in BlackRock’s IBIT

1 day ago

Premium Sponsors

Press Releases

  • REVEALED: The Bitcoin Mining Secret Robinhood Users Use to...

    9 hours ago
  • Why XRP BTC DOGE Enthusiasts and Millionaires Stop Talking...

    9 hours ago
  • Earn Up to $4,5000/Week with Crypto Mining—Why Smart...

    11 hours ago
  • Earn Up to $4,5000/Week with Crypto Mining—Why Smart...

    11 hours ago
  • Earn $7700 a Day – Start a Bitcoin Miner Using...

    12 hours ago

Bitcoin news portal providing breaking news, guides, price analysis about decentralized digital money & blockchain technology.

Join Lightchain AI

Bitcoin

  • News
  • Price
  • Businesses
  • Acceptance
  • Technology
  • Investment
  • Regulation
  • Reviews

Altcoins

  • News
  • Price
  • Ethereum
  • Ripple
  • Litecoin
  • EOS

Categories

  • Blockchain
  • Security
  • FinTech
  • Technology
  • Trending
  • Breaking News
  • Press Releases
  • How to

About Us

  • Advertise
  • Contact us
  • Editorial Policy
  • Privacy Policy
© 2025 Bitcoinist.com. All Rights Reserved.
  • Bitcoin
    • News
    • Price
    • Businesses
    • Acceptance
    • Technology
    • Investment
    • Regulation
    • Reviews
    • All Bitcoin News
  • Altcoins
    • News
    • Price
    • Ethereum
    • Ripple
    • Litecoin
    • EOS
    • NAGA
    • All Altcoin News
  • Tech
    • Blockchain
    • Security
    • FinTech
    • Price
      • Bitcoin Price
      • Ethereum Price
      • Binance Coin Price
      • Litecoin Price
  • Industry
    • Industry News
    • Press Releases
  • How to
    • Buy gift cards/mobile Top Ups with Cryptos
    • What Is Bitcoin?
    • Best Bitcoin Wallet
    • Bitcoin vs Ethereum
    • Why Use Blockchain Technology?
    • Bitcoin Cash ABC vs. Bitcoin Cash SV
    • How to Buy Cryptocurrency
    • How to do Crypto Gambling
      • Crypto Casinos
      • Crypto Betting
    • Play Crypto Games
      • Crypto Poker
      • Crypto Slots
      • Crypto Blackjack
      • Crypto Crash Gambling
      • Plinko
    • Bitcoin Mining
    • Best Bitcoin Brokers
    • Best Bitcoin Forex Brokers
    • How To Earn Bitcoin
    • What is Facebook Libra?
    • Ripple and XRP: The Complete Guide
  • Events
  • Play Games
Advertise

© 2025 Bitcoinist. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Center or Cookie Policy.