2025-03-10 (Back to Inventory)

Lazarus Strikes npm Again with New Wave of Malicious Packages

Author(s): Kirill Boychenko
Organization: Socket

Open article directly   Open article on Archive.org  

Related Articles

2026-07-28SocketSocket Research Team
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
JADESNOW
2026-07-01SocketKarlo Zanki
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
JADESNOW
2026-06-07SocketSocket
Shai-Hulud Descends to Hades: Miasma Worm Campaign Spreads with New PyPI Wave
Shai-Hulud