On npm (Node package management), six malicious packages connected to the well-known North Korean hacker collective Lazarus have been found.
The packages, which have been downloaded 330 times, are made to extract private cryptocurrency data, install backdoors on infected devices, and steal account credentials.
The campaign was uncovered by the Socket Research Team, which connected it to supply chain operations previously identified as Lazarus.
The threat group is well-known for passively breaching systems and introducing harmful packages into software registries like npm, which is utilized by millions of JavaScript developers read more about North Korean Lazarus hackers infect hundreds via npm packages.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
