Skip to content

Malware Alert: Lazarus Targets JavaScript Packages

North Korea’s Lazarus Group Targets npm Packages for Credential Theft

  • Lazarus group linked to six malicious npm packages aimed at stealing credentials.
  • The attack targets files in Google Chrome, Brave, Firefox, and macOS keychains.
  • Packages include is-buffer-validator, yoojae-validator, and others using typosquatting.
  • Over 330 downloads reported; GitHub repositories have been flagged for removal.
  • Lazarus previously linked to $1.4 billion Bybit hack and other crypto heists.

The Lazarus group has deployed six malicious npm packages targeting developers to steal sensitive data from browsers and crypto wallets. Over 330 downloads were reported before actions were taken to remove the packages from GitHub repositories.

Source (2.6)https://decrypt.co/309669/lazarus-javascript-crypto-stealing-malware?rand=52368
Share