logo

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

ID: 1397f2e2-ecdf-53c0-841a-569ee5a64f9c

STIX ID: report--1397f2e2-ecdf-53c0-841a-569ee5a64f9c

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-02-12

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers uncovered a coordinated campaign (graphalgo) using fake recruitment lures and malicious packages on npm and PyPI linked to the North Korea–associated Lazarus Group to deliver a modular RAT with token-based C2; separate npm incidents include the duer-js package deploying Bada Stealer and an XPACK extortion campaign abusing HTTP 402 to force payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.