Tech

New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages

Share
Share


  • Security researchers discovered malicious code in NPM packages and GitHub commits
  • The code was linked to a Lazarus-operated account
  • More than 200 victims were confirmed so far

Lazarus Group, an infamous North Korean state-sponsored threat actor, is running a campaign targeting software and Web3 developers with “undetectable” malware.

Cybersecurity researchers at STRIKE from SecurityScorecard said they observed malware being embedded into GitHub repositories and NPM packages, where unsuspecting developers pick them up and integrate into their own projects.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Amazon says it expects to cut human workers and replace them with AI
Tech

Amazon says it expects to cut human workers and replace them with AI

Amazon CEO Andy Jassy urges workers to be “curious about AI” It...

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions
Tech

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions

Leaked image shows a rounded square design and a large lens Hints...

Microsoft working on next-gen Xbox video game console
Tech

Microsoft working on next-gen Xbox video game console

Credit: CC0 Public Domain Xbox president Sarah Bond on Tuesday confirmed that...