Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. The packages, which have been downloaded 330 times, are designed to steal account credentials, deploy backdoors on compromised systems, and extract sensitive cryptocurrency information. The Socket Research Team discovered the campaign, which linked it to previously known Lazarus supply chain operations. The threat group is known for pushing malicious packages into software registries like npm, which is used by millions of JavaScript developers, and compromising systems passively. Similar campaigns attributed to the same threat actors have been spotted on GitHub and the Python Package Index (PyPI). This tactic often allows them to gain initial access to valuable networks. In some cases, Lazarus uses this access to conduct massive record-breaking attacks, like the recent $1.5 billion crypto heist from the Bybit exchange, though that breach wasn't achieved via a malicious package installation. The six Lazarus packages discovered in npm all employ typosquatting tactics to trick developers into accidental installations: The packages contain malicious code designed to steal sensitive information, such as cryptocurrency wallets and browser data that contains stored passwords, cookies, and browsing history. They also load the BeaverTail malware and the InvisibleFerret backdoor, which North Koreans previously deployed in fake job offers that led to the...
North Korean Lazarus hackers infect hundreds via npm packages
BleepingComputer
·Bill Toulas
·Published Mar 11, 2025
·Updated
Affected Software
7 affected components
npm packages
Chrome browser
Brave Browser
Firefox browser
Solana wallet
Exodus wallet
npm Node Package Manager
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a malware attack by North Korean hackers from the Lazarus group targeting users through malicious npm packages.
2
What security implications are discussed in the article?
The security implications include the risk of credential theft and potential remote code execution from the infected npm packages.
3
What products or software are affected by this attack?
The attack affects npm packages, and potentially users of Chrome, Brave, Firefox browsers, Solana wallet, and Exodus wallet.
4
How many malicious npm packages were identified?
Six malicious npm packages linked to the Lazarus group were identified in the report.
5
How many times were these malicious packages downloaded?
The malicious packages have been downloaded approximately 330 times.