Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Lazarus Expands Malicious npm Campaign: 11 New Packages Add ...

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
1,054
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

Lazarus Group has intensified its malicious npm campaign by introducing 11 new packages that act as malware loaders with over 5,600 downloads, utilizing hex obfuscation techniques to evade detection, and targeting developers to steal credentials and maintain system access. The North Korean threat actors behind the Contagious Interview operation have expanded their presence in the npm ecosystem, delivering the BeaverTail malware and new remote access trojan (RAT) loaders. These malicious packages, distributed under both old and new aliases, mimic utilities for arrays, logging, debugging, and API handling, and are linked to both GitHub and Bitbucket repositories to appear legitimate. The packages incorporate tight loops for data extraction from browser profiles, particularly targeting Solana's private keys, with exfiltration occurring silently via HTTP POST requests. The threat actors continue to create new accounts to distribute these packages, demonstrating persistence and adaptability in their tactics. Organizations are advised to enhance their software supply chain security by implementing automated dependency audits and monitoring for unusual dependency changes to mitigate the risks posed by this ongoing threat.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.