Japan warns of malicious PyPi packages created by North Korean hackers
ID: 1415efdb-c745-566c-add0-9f816cfea497
STIX ID: report--1415efdb-c745-566c-add0-9f816cfea497
Feed Name: Bleeping Computer
JPCERT/CC warns that Lazarus uploaded four malicious PyPI packages that deploy the Comebacker loader by embedding XOR-encoded DLLs inside a file named test.py which is decoded and executed by __init__.py; the final in-memory payload phones home to a C2 and can load additional Windows malware. PePy reported ~3,252 installs before the packages were removed, indicating active exploitation and supply-chain risk to developers, with ties to prior Lazarus campaigns targeting crypto and developer ecosystems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
