logo

Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems

ID: 89a45672-42c0-5b81-a930-f9292075d426

STIX ID: report--89a45672-42c0-5b81-a930-f9292075d426

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-02-29

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Lazarus (North Korea) uploaded four typosquatting packages to PyPI (pycryptoenv, pycryptoconf, quasarlib, swapmempool) that were downloaded ~3,269 times; the packages hid an XOR-encoded DLL inside a test.py which produced IconCache.db and NTUSER.DAT, used NTUSER.DAT to load IconCache.db (Comebacker) that connects to a C2 to fetch and run a Windows executable, representing an active supply-chain campaign targeting developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.