More

    New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages




    • Security researchers discovered malicious code in NPM packages and GitHub commits
    • The code was linked to a Lazarus-operated account
    • More than 200 victims were confirmed so far

    Lazarus Group, an infamous North Korean state-sponsored threat actor, is running a campaign targeting software and Web3 developers with “undetectable” malware.

    Cybersecurity researchers at STRIKE from SecurityScorecard said they observed malware being embedded into GitHub repositories and NPM packages, where unsuspecting developers pick them up and integrate into their own projects.

    https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img