logo

Fake password manager coding test used to hack Python developers

ID: 1c8aee9f-f68e-53d9-b9b6-743a30540bb2

STIX ID: report--1c8aee9f-f68e-53d9-b9b6-743a30540bb2

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-09-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

ReversingLabs and reporting detail a Lazarus APT campaign (VMConnect) that targets Python developers with fake password-manager coding tests hosted on GitHub and malicious PyPI packages; the README instructs victims to run a provided application which triggers a base64-obfuscated downloader embedded in library __init__.py files that contacts a command-and-control server. Attackers impersonate recruiters (including large banks) on LinkedIn and impose tight time limits to discourage code review; activity was observed as recently as July 31 and developers are advised to verify recruiters and execute untrusted code only in isolated sandboxes or VMs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.