Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers
ID: 6fbfd5db-7bf8-5cb5-8e01-58b4644bd46c
STIX ID: report--6fbfd5db-7bf8-5cb5-8e01-58b4644bd46c
Feed Name: cybersecurityNews.com
Threat Score
**Executive summary:** Between January and July 2025 the Lazarus Group (North Korean state‑sponsored actor) deployed 234 malicious packages to npm and PyPI that masqueraded as legitimate developer tools, exposing over 36,000 potential victims to espionage implants capable of stealing credentials, profiling hosts, and establishing persistent backdoors by abusing developer trust, decentralized project maintenance, and automated CI/CD propagation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
