Malicious npm Packages Steal Developer Credentials in Lazarus Campaign
Hamid Siddiqui
News
No image for this briefing
Security researchers at JFrog have uncovered six malicious npm packages, linked to North Korean threat actors, impersonating Rollup polyfill tools. These packages were designed to steal developer credentials and enable remote access. They used a deceptive delivery method and have been removed from the npm registry. The campaign embodies a repeated trend of supply chain attacks targeting open-source repositories.