logo

Japan Blames North Korea for PyPI Supply Chain Cyberattack

ID: e37ea4ed-8093-5955-8fbc-2409f98d128e

STIX ID: report--e37ea4ed-8093-5955-8fbc-2409f98d128e

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-03-11

Date Updated: 2026-04-21

Author: John Leyden, Contributing Writer

...
...

Japanese authorities warned that the Lazarus Group carried out a typosquatting supply-chain campaign on PyPI by publishing malicious packages (e.g., "pycryptoenv", "pycryptoconf") that install the Comebacker Trojan on Windows systems; the packages were downloaded roughly 300–1,200 times and can enable credential theft, ransomware deployment, and pipeline infiltration, prompting recommendations for stronger package vetting, SCA tools, and platform-level protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.