Fake recruiter coding tests target devs with malicious Python packages
2024-09-10 • Reversing Labs •
ReversingLabs links new malicious Python packages to VMConnect, a campaign previously associated with North Korea's Lazarus Group through Japan CERT research and code similarities. The activity targets developers through fake recruiter and coding-test lures hosted in GitHub projects, including archives such as Python_Skill_Assessment.zip and README instructions that push candidates to run the project before editing it. The malware hides downloader logic in compiled PYC files and matching plaintext Python files, giving the campaign a path to execute even when source files are not inspected. ReversingLabs also identified one compromised developer and observed attackers impersonating employees of major financial-services firms.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6a8b8bbd83ea4cfeaadaf397700f756… | 2024-09-10 | 2024-09-10 |