Researchers from Ransom-ISAC, Bridewell, and Crystal Intelligence detailed a malware campaign that used a weaponized private GitHub repository and Telegram-based fake job lures to target developers, delivering a multi-stage infection chain built around Cross-Chain TxDataHiding. In the observed September 2025 intrusion, a trojanized node-react-e-commerce project hid encrypted JavaScript payloads and command data in blockchain transactions, using TRON or Aptos records as pointers to Binance Smart Chain data and later expanding across Ethereum, Aurora, and other chains. The malware chain included the JavaScript RAT DEV#POPPER.js and the Python stealer OmniStealer, enabling cross-platform execution on Windows, macOS, and Linux, persistence through VSCode and Cursor IDE modification, and theft of credentials, browser artifacts, wallet data, environment variables, and developer secrets.
Investigators said the campaign paired blockchain-hosted payload delivery with conventional HTTP and socket.io command-and-control infrastructure, including clusters tied to Evoxt, Clouvider, PJSC Megafon, and a Russia-linked RDP setup, while some infrastructure also overlapped with IPs previously reported in 2025 NPM supply-chain compromises. A later financial-forensics investigation attributed the broader blockchain malware infrastructure to North Korean threat actors by tracing operational wallets through bridges, swap services, and laundering hubs including Huione, Xinbi Guarantee, and BlackU, and by linking funding flows to wallets associated with documented DPRK cryptocurrency thefts, including the Bybit theft. Researchers also cited weekday working-hour patterns, rotating C2 servers, and one wallet access event from IP 188.43.33.249 in Vladivostok consistent with known DPRK routing, concluding that the attackers built a hard-to-disrupt on-chain malware and C2 ecosystem designed for stealth, resilience, and cryptocurrency theft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Crystal Intelligence reported that the Cross-Chain TxDataHiding malware operations continued through November 2025. Throughout this period, operators rotated command-and-control servers while maintaining blockchain-based infrastructure.
Ransom-ISAC and Bridewell analyzed the September 2025 campaign infrastructure and expanded the original four C2 IPs into multiple HTTP API, socket.io, RDP, and HTTP 302 redirection clusters. The work linked high-confidence infrastructure to Evoxt-hosted servers and identified additional lower-confidence clusters across other providers.
The September 2025 intrusion chain delivered a cross-platform Node.js RAT dubbed DEV#POPPER.js and a Python information stealer named OmniStealer. The malware provided remote code execution, persistence in VS Code and Cursor files, and theft of wallets, credentials, browser data, source code, and developer secrets.
Ransom-ISAC documented a novel malware delivery method it named Cross-Chain TxDataHiding, in which TRON or Aptos transactions pointed to encrypted payloads stored in Binance Smart Chain transaction input data. The technique used blockchain data as a resilient command-and-control and payload retrieval layer.
In September 2025, attackers used a fake blockchain-related job approach over LinkedIn and Telegram to lure a developer into a private GitHub repository named store-v impersonating node-react-e-commerce. The repository contained the initial malicious JavaScript stager in Tailwind.config.js.
Crystal Intelligence and Ransom-ISAC reported that the blockchain-hosted malware operations began in early June 2025. From that point, operators used rotating command-and-control servers and blockchain transaction data to support the campaign.
The infrastructure analysis found that several identified IP addresses overlapped with Aikido reporting on 2025 NPM supply-chain compromises. The overlap supported the assessment that the intrusion was likely related to that broader campaign.
The financial tracing showed funds moving through legitimate services, bridges, swaps, and layered transactions between October 2024 and April 2025. Investigators said these flows appeared normal in isolation but formed part of the operational funding chain for the malware infrastructure.
Investigators found some infrastructure wallets had been funded and then remained dormant since 2021 before later being activated for malware operations. The report cites this as evidence of multi-year operational planning behind the campaign.
The blockchain analysis also found medical records, chest X-rays, legal documents, and audio files embedded in transactions unrelated to direct malware delivery. The report interpreted these artifacts as systematic testing of blockchain-based operational tradecraft and file-handling methods.
Crystal Intelligence and Ransom-ISAC attributed the Cross-Chain TxDataHiding infrastructure campaign to North Korean threat actors by tracing operational wallet funding backward through bridges, swaps, and layered transactions. The investigation linked campaign wallets to documented DPRK theft activity, including the Bybit theft, and to laundering hubs such as Huione, Xinbi Guarantee, and BlackU.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
crystalintelligence.com
Open sourceransom-isac.org
Open sourceransom-isac.org
Open sourceransom-isac.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.