logo

New Malicious PyPI Packages used by Lazarus

ID: b9491312-6e87-54be-ae1b-1a050eecd93a

STIX ID: report--b9491312-6e87-54be-ae1b-1a050eecd93a

Feed Name: JPCERT Blog

Threat Score
85/100

Date Published: 2024-02-28

Date Updated: 2026-04-19

Author: 朝長 秀誠 (Shusei Tomonaga)

...
...

JPCERT/CC confirms that the Lazarus APT published multiple malicious Python packages on PyPI (pycryptoenv, pycryptoconf, quasarlib, swapmempool) using typosquatting to distribute Comebacker malware; the packages contain XOR-encoded DLLs decoded and executed via rundll32, with network C2 POST behavior, listed C2 domains/IPs, file hashes, and PDBs provided as IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.