북한 라자루스(Lazarus) 그룹이 배포한 악성 npm 패키지 감염 사례

2025-03-17 Logpresso Infection Cases Involving Malicious npm Packages Distributed by North Korea’s Lazarus Group

https://logpresso.com/ko/blog/2025-03-17-lazarus-npm

Thumbnail for 북한 라자루스(Lazarus) 그룹이 배포한 악성 npm 패키지 감염 사례

Lazarus is reported to have distributed six malicious npm packages through typosquatting and package impersonation, exposing developers to credential theft, sensitive data collection, backdoor installation, and malicious code execution during software builds. The campaign is a supply-chain threat because compromised developer environments can propagate risk into applications and downstream users who trust packages pulled from the npm ecosystem.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.137.213.30 2025-03-17 2025-11-13
IPv4 94.131.97.195 2025-03-17 2025-11-13
IPv4 45.61.150.31 2025-03-17 2025-11-13
IPv4 144.172.97.7 2025-03-17 2025-11-13
IPv4 172.86.84.38 2025-03-10 2025-11-13
IPv4 45.128.52.14 2025-01-29 2025-11-13
IPv4 185.153.182.241 2025-01-29 2025-11-13
IPv4 86.104.74.51 2024-12-03 2025-11-13
IPv4 185.235.241.208 2024-08-13 2025-11-13
HASH f08e3ee84714cc5faefb7ac300485c8… 2025-03-17 2025-10-16
HASH 6a104f07ab6c5711b6bc8bf6ff956ab… 2024-10-23 2025-07-26
IPv4 144.172.86.27 2025-03-17 2025-05-13
HASH ab7608bc7af2c4cdf682d3bf065dd30… 2025-03-17 2025-04-25
HASH bb8fbaeb629eeeef11646a0cb97fdb34 2025-03-17 2025-03-17
HASH 31ed238577c0ed82ee93e4a10a8fb542 2025-03-17 2025-03-17
HASH 4682e781d34990d6684cea7e442268d… 2025-03-17 2025-03-17
HASH efbc268a345e5a3089ca0640353b98cc 2025-03-17 2025-03-17
HASH 2844daa31c0b3dc9821e8790d7f6be7… 2025-03-17 2025-03-17
HASH 5634b1b3c17cf4dc2f9eb51ab55abd9… 2025-03-17 2025-03-17
HASH 277527242bb88727cc231ee68f3ce6a… 2025-03-17 2025-03-17
HASH fba7016fc7cdd9d3247fa2e11be358c… 2025-03-17 2025-03-17
HASH 617205f5a241c2712d4d0a3b06ce3afd 2025-03-17 2025-03-17
HASH 085b6e68407a0a0053aa25e8c9d62586 2025-03-17 2025-03-17
HASH 42595da250a90129217f1dea56bfbbd… 2025-03-17 2025-03-17
HASH f969b669e6c3d83afbf3b798cd22ead… 2025-03-17 2025-03-17
HASH a2190824ca378c0de1a97170032ba64… 2025-03-17 2025-03-17
HASH 6dbb9e6abc8e403309954800986e431… 2025-03-17 2025-03-17
HASH 31d1f186d805ebe71069d071ea95a9fc 2025-03-17 2025-03-17
HASH 17fefe3013f8ae82281747cd20b0adc… 2025-03-17 2025-03-17
HASH 2afa2a236f34c1c8b58ec0f27c571abc 2025-03-17 2025-03-17
HASH 23e3086d22be13bba02bb246f0fd9f8a 2025-03-17 2025-03-17
HASH 2a40efbef15faac978a2006f65017a8… 2025-03-17 2025-03-17
HASH 906ea1d2a802407587b3a4fb95d8e588 2025-03-17 2025-03-17
HASH b5aef5763ef9bb87c4794c89731f278… 2025-03-17 2025-03-17
HASH d957ea41dbbc3c9666811c07663ff1f… 2025-03-17 2025-03-17
HASH 1d7709aee3b9dcd1f58794abccc8b83… 2025-03-17 2025-03-17
HASH 953c431bdfa8f7318d96883afe4ef083 2025-03-17 2025-03-17
HASH 36b94c5b24ed6646cedc7cb64e2acabd 2025-03-17 2025-03-17
HASH bd2266101b5e01588cda8fac84fa80f… 2025-03-17 2025-03-17
HASH 748d01320660cfe183d5fa06165c82b… 2025-03-17 2025-03-17
HASH f91bb20852c14222a0c193ce50c7042d 2025-03-17 2025-03-17
HASH fc5f0b1242c79576a3c4c13111f9a79e 2025-03-17 2025-03-17
HASH e0660b4df0f01b4311230987e05ef1a… 2025-03-17 2025-03-17
HASH 2e5f8c8c13e25d91b2a3deb900b9093… 2025-03-17 2025-03-17
HASH bc644febfc0a9500bcc24d26fbfa9cae 2025-03-17 2025-03-17
HASH f01ab3aba077f34c86511b0c14326bf… 2025-03-17 2025-03-17
HASH 38d365898fd6acbb4788e654e864922d 2025-03-17 2025-03-17
HASH 540c67abd772a0535eb2b72cb2a575f… 2025-03-17 2025-03-17
HASH 056d95216a949d02a6e7a4452aa0310… 2025-03-17 2025-03-17
HASH d61fd1a98ec6f6bbb56baaf9e9d64a4… 2025-03-17 2025-03-17
HASH 176b980270ebf5bcd3b0d1c855da42f… 2025-03-17 2025-03-17
HASH e39811264e74ef13cbf5a71d3180362… 2025-03-17 2025-03-17
HASH 8d513c1fee0bce5d6cc5070b7d73340… 2025-03-17 2025-03-17
HASH be048020bcd95b23f422959a376418f8 2025-03-17 2025-03-17
HASH 8907fe74ee2d2ae821d31e376a6c13f9 2025-03-17 2025-03-17
HASH ab8bf3bb0bfdaeb699d5e88cf4e8789… 2025-03-17 2025-03-17
HASH 675c3c7af3a9b9deb2fb2f132a84c8a… 2025-03-17 2025-03-17
HASH 350da6c37d869fd164e44edde2fed57e 2025-03-17 2025-03-17
HASH 51e1770e6117d7aeef4cc6628d5cf6e… 2025-03-17 2025-03-17
HASH 1d36f6710bab789cc6c0be05e4c0901… 2025-03-17 2025-03-17
HASH c7789d4bc0a39c3242b7500c7c05fb7… 2025-03-17 2025-03-17
HASH 6bc11397639028acfe562d2b15718d9f 2025-03-17 2025-03-17
HASH ff29722e913038c4f0e99373d22dc87… 2025-03-17 2025-03-17
HASH 7df4dce39c8a1624ae7988b65def5ff7 2025-03-17 2025-03-17
HASH b944232645a1203c8d63cc952fd3040… 2025-03-17 2025-03-17
HASH 656eab9b23906ac7f0ff0eecd507797… 2025-03-17 2025-03-17
HASH b5ac988fad1fdcaaa1fbb069de11dce… 2025-03-17 2025-03-17
HASH 712cc918e6c703d006934428a9d92d2… 2025-03-17 2025-03-17
HASH 1697bf8bea8bcd1835961c33da4c23b… 2025-03-17 2025-03-17
HASH 281c2f8060dd3f0b244ae2282c3d3d4… 2025-03-17 2025-03-17
URL http://zkservice.cloud/api/serv… 2025-03-17 2025-03-17
URL http://zkservice.cloud/api/v2/p… 2025-03-17 2025-03-17
DOMAIN zkservice.cloud 2025-03-17 2025-03-17
IPv4 45.61.128.110 2025-03-17 2025-03-17
HASH 48c179680e0b37d0262f7a402860b2a7 2025-01-20 2025-03-17

Related Actors

Related Reports

« Back