Lazarus Group Targets npm with Malicious Packages to Steal Credentials and Crypto

Listen to this Post

A New Wave of Software Supply Chain Attacks

A new cybersecurity threat has emerged as six malicious packages were identified on npm (Node Package Manager), linked to the infamous Lazarus hacking group from North Korea. These malicious packages have been downloaded 330 times, allowing hackers to steal sensitive data, deploy backdoors, and extract cryptocurrency information from compromised systems.

The Socket Research Team uncovered this campaign and linked it to previous supply chain attacks by Lazarus. The group has a history of injecting harmful packages into widely used software repositories like npm, GitHub, and PyPI (Python Package Index), leveraging these platforms to gain stealthy, initial access to high-value networks.

This latest attack is reminiscent of previous campaigns by Lazarus, including the staggering $1.5 billion crypto heist from the Bybit exchange. The hackers use typosquatting tactics, mimicking legitimate package names to deceive developers into installing their malicious software.

The Six Malicious Packages on npm

  1. is-buffer-validator – Mimics the legitimate is-buffer package to steal credentials.
  2. yoojae-validator – Extracts sensitive system data from infected machines.
  3. event-handle-package – Disguised as an event-handling tool but deploys a backdoor for remote access.

4. array-empty-validator – Steals system and browser credentials.

  1. react-event-dependency – Poses as a React utility but executes malware in developer environments.
  2. auth-validator – Mimics authentication libraries to steal login credentials and API keys.

How These Malicious Packages Work

Once installed, these packages steal cryptocurrency wallets, browser credentials, and sensitive user data. They load the BeaverTail malware and InvisibleFerret backdoor, which Lazarus previously used in phishing campaigns disguised as fake job offers.

The malware systematically collects system environment details, scanning browser profiles for sensitive files like:

– Login credentials from Chrome, Brave, and Firefox

– Keychain archives on macOS

  • id.json files from Solana and Exodus crypto wallets

Shockingly, these packages are still available on npm and GitHub, posing an ongoing threat. Developers are urged to carefully vet third-party libraries, inspect code for suspicious behavior, and monitor unexpected calls to external servers.

What Undercode Says:

The Lazarus Group’s strategy is evolving, and their reliance on software supply chain attacks has proven highly effective. By injecting malware into commonly used development tools, they exploit the trust that developers place in open-source repositories.

Why These Attacks Are Dangerous

1. Targeting Developers Directly

  • Unlike traditional phishing campaigns, these attacks compromise developer environments from the start.
  • Once inside, they can propagate malware to software being built and deployed.

2. High-Value Data Extraction

  • The focus on cryptocurrency wallets suggests a strong financial motivation.
  • By compromising development environments, they also gain access to enterprise credentials and internal systems.

3. Persistence & Stealth

  • The use of BeaverTail and InvisibleFerret backdoors allows hackers to maintain long-term access.
  • These tools let them steal data over time, making it harder to detect breaches immediately.

The Lazarus

Lazarus is not new to software supply chain manipulation. In the past, they have:

– Infiltrated PyPI with Python-based malware.

– Compromised GitHub repositories to spread trojans.

– Leveraged npm to attack JavaScript-based projects.

Their tactics align with a growing trend where nation-state actors use supply chain attacks to breach large networks with minimal effort.

How Developers Can Stay Safe

– Always verify npm packages before installing

  • Check for unusual code obfuscation and external server calls

– Monitor updates for installed dependencies

  • Use security tools like Socket, Snyk, and npm audit

Future Implications

This attack highlights an urgent need for stronger security measures in open-source ecosystems. The lack of a centralized security standard makes it easy for attackers to exploit package managers like npm, PyPI, and GitHub.

If unchecked, supply chain attacks will continue to rise, impacting major businesses and developers worldwide.

Fact Checker Results

  • Confirmed: The six malicious npm packages are still active and accessible.
  • Verified: Lazarus has previously used similar tactics in PyPI and GitHub attacks.
  • Alert: Developers should take immediate action to verify their dependencies.

The Lazarus Group’s npm attack is a wake-up call for the entire software development community. Developers must remain vigilant, security teams must strengthen package monitoring, and open-source ecosystems need better security enforcement to prevent future breaches.

References:

Reported By: https://www.bleepingcomputer.com/news/security/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/
Extra Source Hub:
https://www.github.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp
💬 TelegramFeatured Image