logo

Lazarus Group’s Latest: Brandjacking Campaign on npm

ID: 4d780296-1f3f-5a65-8454-9ecd65cf382c

STIX ID: report--4d780296-1f3f-5a65-8454-9ecd65cf382c

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

Author: Sonatype Security Research Team

...
...

Sonatype Security Research reports a Lazarus Group campaign on npm using brandjacking (suffixes, embedding, version mimicry) across dozens of packages to masquerade as legitimate developer libraries; analysis of the buffer-utilities package revealed a dropper that fetches and executes remote payloads. Organizations that installed affected packages are advised to remove them, investigate for second-stage activity, and treat impacted hosts as potentially compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.