logo

North Korea targets crypto developers via NPM supply chain attack

ID: fcf852c6-a44a-5e1b-bf8e-3c2f3b88f5b0

STIX ID: report--fcf852c6-a44a-5e1b-bf8e-3c2f3b88f5b0

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-02-13

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Operation Marstech Mayhem: SecurityScorecard found a Lazarus Group campaign that embeds a highly obfuscated JavaScript implant (Marstech1) into GitHub repositories and NPM packages used by crypto developers to scan for and exfiltrate wallet data across Windows, macOS, and Linux (233 victims confirmed); the report also notes a separate Kimsuky social‑engineering technique that lures targets into running PowerShell to install remote access and credential‑harvesting tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.