CandleFocus

Report: Lazarus Group Exploits Github, NPM Packages in Cryptocurrency Malware Campaign   

Report: Lazarus Group Exploits Github, NPM Packages in Cryptocurrency Malware Campaign   
A North Korean cyber collective called Lazarus Group has been targeting Github repositories and NPM modules to steal digital currencies. They have injected malicious code into Github projects and exploited weaknesses in software supply chains to spread their malware called Marstech1. This malware infiltrates cryptocurrency wallets and redirects transactions without detection. The Securityscorecard STRIKE Team has verified 233 compromised entities across the US, Europe, and Asia, with Lazarus-linked scripts operational since July 2024. This incident highlights the growing threat of open-source malware and the need for strengthened security measures in development pipelines.

Related News