Tech

New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages

Share
Share


  • Security researchers discovered malicious code in NPM packages and GitHub commits
  • The code was linked to a Lazarus-operated account
  • More than 200 victims were confirmed so far

Lazarus Group, an infamous North Korean state-sponsored threat actor, is running a campaign targeting software and Web3 developers with “undetectable” malware.

Cybersecurity researchers at STRIKE from SecurityScorecard said they observed malware being embedded into GitHub repositories and NPM packages, where unsuspecting developers pick them up and integrate into their own projects.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Seeing through a new LENS allows brain-like navigation in robots
Tech

Seeing through a new LENS allows brain-like navigation in robots

Dr. Adam Hines, with his ‘green’ robot. l/r- Dr. Tobias Fischer, Dr....

Prime Day now lasts four days – here are my 6 tips to grab the biggest bargains
Tech

Prime Day now lasts four days – here are my 6 tips to grab the biggest bargains

Well, we all knew Prime Day was on the horizon, and Amazon...

AMD shifts to modular GPU strategy with MI355X, ending MI300A-style APU designs
Tech

AMD shifts to modular GPU strategy with MI355X, ending MI300A-style APU designs

MI355X leads AMD’s new MI350 Series with 288GB memory and full liquid-cooled...

Amazon hopes to deliver 10,000 robotaxis annually with new factory, challenging Waymo
Tech

Amazon hopes to deliver 10,000 robotaxis annually with new factory, challenging Waymo

In this undated handout photo provided by Zoox, Zoox robotaxis are assembled...