logo

Japan warns of malicious PyPi packages created by North Korean hackers

ID: 1415efdb-c745-566c-add0-9f816cfea497

STIX ID: report--1415efdb-c745-566c-add0-9f816cfea497

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-02-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

JPCERT/CC warns that Lazarus uploaded four malicious PyPI packages that deploy the Comebacker loader by embedding XOR-encoded DLLs inside a file named test.py which is decoded and executed by __init__.py; the final in-memory payload phones home to a C2 and can load additional Windows malware. PePy reported ~3,252 installs before the packages were removed, indicating active exploitation and supply-chain risk to developers, with ties to prior Lazarus campaigns targeting crypto and developer ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.