Lazarus Hackers Use 234 Weaponized npm and PyPI Packages to Target Developers
ID: afa0a918-25a7-50c7-9f10-62e7ec44a95a
STIX ID: report--afa0a918-25a7-50c7-9f10-62e7ec44a95a
Feed Name: Cyber Press
Threat Score
### Executive summary Sonatype identified a sophisticated Lazarus Group supply-chain campaign (Jan–Jul 2025) that planted 234 malicious packages on npm and PyPI designed to harvest credentials, profile developer hosts, and install persistent backdoors; the firm blocked these packages and estimated over 36,000 potential victims, highlighting a strategic shift by the nation-state actor toward long-term infiltration of developer ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
