• News/
  • https://www.bleepingcomputer.com/news/security/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/

North Korean Lazarus hackers infect hundreds via npm packages

BleepingComputer
·
Bill Toulas
·
Published Mar 11, 2025
·
Updated

Six malicious packages have been identified on npm (Node package manager) linked to the notorious North Korean hacking group Lazarus. The packages, which have been downloaded 330 times, are designed to steal account credentials, deploy backdoors on compromised systems, and extract sensitive cryptocurrency information. The Socket Research Team discovered the campaign, which linked it to previously known Lazarus supply chain operations. The threat group is known for pushing malicious packages into software registries like npm, which is used by millions of JavaScript developers, and compromising systems passively. Similar campaigns attributed to the same threat actors have been spotted on GitHub and the Python Package Index (PyPI). This tactic often allows them to gain initial access to valuable networks. In some cases, Lazarus uses this access to conduct massive record-breaking attacks, like the recent $1.5 billion crypto heist from the Bybit exchange, though that breach wasn't achieved via a malicious package installation. The six Lazarus packages discovered in npm all employ typosquatting tactics to trick developers into accidental installations: The packages contain malicious code designed to steal sensitive information, such as cryptocurrency wallets and browser data that contains stored passwords, cookies, and browsing history. They also load the BeaverTail malware and the InvisibleFerret backdoor, which North Koreans previously deployed in fake job offers that led to the...

Read full article

Affected Software

7 affected components
npm packages
Chrome browser
Brave Browser
Firefox browser
Solana wallet
Exodus wallet
npm Node Package Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a malware attack by North Korean hackers from the Lazarus group targeting users through malicious npm packages.

2

What security implications are discussed in the article?

The security implications include the risk of credential theft and potential remote code execution from the infected npm packages.

3

What products or software are affected by this attack?

The attack affects npm packages, and potentially users of Chrome, Brave, Firefox browsers, Solana wallet, and Exodus wallet.

4

How many malicious npm packages were identified?

Six malicious npm packages linked to the Lazarus group were identified in the report.

5

How many times were these malicious packages downloaded?

The malicious packages have been downloaded approximately 330 times.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203