logo

North Korean APT Lazarus Uses Malicious npm Package to Target Developers

ID: 689f36f5-6a6c-54b7-a62c-1b9d8d5a2ea8

STIX ID: report--689f36f5-6a6c-54b7-a62c-1b9d8d5a2ea8

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2025-02-03

Date Updated: 2026-04-22

Author: do son

...
...

Researchers uncovered a Lazarus Group supply-chain attack delivering BeaverTail via a malicious npm package (postcss-optimizer) that mimics a widely used library; the package (477 downloads) establishes persistence, fetches secondary payloads, and steals browser credentials, cryptocurrency wallet keys (MetaMask, Phantom, Binance Wallet, Coinbase Wallet, Solana keys), and macOS keychain data while communicating with a hardcoded C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.