Lazarus Group Targets Developers Through NPM Packages and Supply Chain Attacks
ID: ddb420d6-bfd9-5848-b7c1-d845ec2cc8f1
STIX ID: report--ddb420d6-bfd9-5848-b7c1-d845ec2cc8f1
Feed Name: SecurityScorecard Blog
Operation Marstech Mayhem is a Lazarus Group campaign that targets software developers and open‑source supply chains by embedding an obfuscated multistage JavaScript implant (Marstech1) in fake GitHub repositories and compromised NPM packages; the implant persists in developer environments, exfiltrates cryptocurrency wallet data (Exodus, Atomic, MetaMask) across Windows, macOS, and Linux, and communicates with Node.js/Express C2 servers on port 3000. STRIKE attributes the activity to Lazarus, notes advanced obfuscation and anti‑analysis techniques (Base85 + XOR, control flow flattening, self‑invoking functions, anti‑debugging), and has confirmed 233 victims, recommending code source verification, dependency audits, network monitoring, and endpoint protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
