Malicious npm Packages Steal Developer Credentials in Lazarus Campaign

Hamid Siddiqui News
No image for this briefing
Security researchers at JFrog have uncovered six malicious npm packages, linked to North Korean threat actors, impersonating Rollup polyfill tools. These packages were designed to steal developer credentials and enable remote access. They used a deceptive delivery method and have been removed from the npm registry. The campaign embodies a repeated trend of supply chain attacks targeting open-source repositories.

More in News

All briefings

Read more in AiShorts