Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems
ID: 89a45672-42c0-5b81-a930-f9292075d426
STIX ID: report--89a45672-42c0-5b81-a930-f9292075d426
Feed Name: The Hacker News
Threat Score
Lazarus (North Korea) uploaded four typosquatting packages to PyPI (pycryptoenv, pycryptoconf, quasarlib, swapmempool) that were downloaded ~3,269 times; the packages hid an XOR-encoded DLL inside a test.py which produced IconCache.db and NTUSER.DAT, used NTUSER.DAT to load IconCache.db (Comebacker) that connects to a C2 to fetch and run a Windows executable, representing an active supply-chain campaign targeting developers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
