logo

Supply Chain Hackers LofyGang Behind Hundreds of Malicious Packages

ID: 61c03cf1-f86b-5701-8dca-8c634f3c3d7b

STIX ID: report--61c03cf1-f86b-5701-8dca-8c634f3c3d7b

Feed Name: Security Ledger

Threat Score
80/100

Date Published: 2022-10-10

Date Updated: 2026-04-26

Author: Farwa Sajjad

...
...

Checkmarx Labs reports that an organized Brazilian cybercriminal group called LofyGang published ~200 malicious open-source packages (linked to thousands of supply-chain attacks) across ecosystems like GitHub and NPM, using techniques such as starjacking and typosquatting and hiding malicious payloads in secondary dependencies; the group monetizes stolen credit cards and account data via Discord/YouTube communities, and Checkmarx published IOCs and tracking resources to map the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.