North Korea's Lazarus Group has launched a new campaign spreading through npm packages, using BeaverTail malware to target developers and cryptocurrency users. The malicious packages, downloaded over 300 times, aim to steal login credentials, deploy backdoors, and extract sensitive data from Solana-related cryptocurrency wallets or Exodus. The packages use typosquatting to trick developers into installing them. The stolen data is sent to a C2 server following Lazarus's strategy of harvesting and transmitting compromised information. Lazarus has previously used supply chain attacks to infiltrate networks, contributing to major hacks such as the $1.5 billion Bybit exchange heist.



Other News from Today