logo

Lazarus Hackers Weaponized 234 Packages Across npm and PyPI to Infect Developers

ID: 6fbfd5db-7bf8-5cb5-8e01-58b4644bd46c

STIX ID: report--6fbfd5db-7bf8-5cb5-8e01-58b4644bd46c

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-08-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** Between January and July 2025 the Lazarus Group (North Korean state‑sponsored actor) deployed 234 malicious packages to npm and PyPI that masqueraded as legitimate developer tools, exposing over 36,000 potential victims to espionage implants capable of stealing credentials, profiling hosts, and establishing persistent backdoors by abusing developer trust, decentralized project maintenance, and automated CI/CD propagation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.