Tech

New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages

Share
Share


  • Security researchers discovered malicious code in NPM packages and GitHub commits
  • The code was linked to a Lazarus-operated account
  • More than 200 victims were confirmed so far

Lazarus Group, an infamous North Korean state-sponsored threat actor, is running a campaign targeting software and Web3 developers with “undetectable” malware.

Cybersecurity researchers at STRIKE from SecurityScorecard said they observed malware being embedded into GitHub repositories and NPM packages, where unsuspecting developers pick them up and integrate into their own projects.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
South Korea’s LG Energy Solution exits from .4bn Indonesia project
Tech

South Korea’s LG Energy Solution exits from $8.4bn Indonesia project

Credit: Unsplash/CC0 Public Domain South Korea’s LG Energy Solution said Tuesday it...

The Oscars’ new AI rule provides a tentative green light for generative tech in movies
Tech

The Oscars’ new AI rule provides a tentative green light for generative tech in movies

Ahead of the 98th Oscars ceremony, scheduled for March 2026, the Academy...

US urges curb of Google’s search dominance as AI looms
Tech

US urges curb of Google’s search dominance as AI looms

Google contends the US is overreaching by asking a federal judge to...

Auto Shanghai to showcase electric competition at sector’s new frontier
Tech

Auto Shanghai to showcase electric competition at sector’s new frontier

The Shanghai auto show is the world’s biggest and will showcase some...