EN / ES / HU
cybersecurity

Lazarus Group's Latest: Brandjacking Campaign on npm

Source: sonatype.com 1 min read

Share

Lazarus Group's Latest: Brandjacking Campaign on npm

You are reading a summary. The full content is hosted on sonatype.com.

Sonatype reports a Lazarus Group npm campaign using dozens of malicious, brandjacking packages that mimic trusted ecosystems to deliver follow-on payloads. Analysis of buffer-utilities shows a dropper that fetches and executes remote code and can establish persistent attacker-controlled activity, so affected installs should be treated as potentially compromised.

Related Articles