logo

Bogus npm Packages Used to Trick Software Developers into Installing Malware

ID: ef854600-0425-5ecf-9b30-4326e5f6e23c

STIX ID: report--ef854600-0425-5ecf-9b30-4326e5f6e23c

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-04-27

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Securonix and other security firms are tracking DEV#POPPER, a social-engineering campaign that impersonates employers in fake job interviews to coerce developers into downloading malicious npm packages or GitHub-hosted ZIPs. The delivered payloads include a Node.js information stealer called BeaverTail and a Python backdoor named InvisibleFerret, enabling data theft, command execution, file exfiltration, and keystroke/clipboard logging; reporting links this activity to North Korean APTs such as groups associated with Lazarus.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.