Fake recruiter coding tests target devs with malicious Python packages

2024-09-10 Reversing Labs

https://www.reversinglabs.com/blog/fake-recruiter-coding-tests-target-devs-with-malicious-python-packages

Thumbnail for Fake recruiter coding tests target devs with malicious Python packages

ReversingLabs links new malicious Python packages to VMConnect, a campaign previously associated with North Korea's Lazarus Group through Japan CERT research and code similarities. The activity targets developers through fake recruiter and coding-test lures hosted in GitHub projects, including archives such as Python_Skill_Assessment.zip and README instructions that push candidates to run the project before editing it. The malware hides downloader logic in compiled PYC files and matching plaintext Python files, giving the campaign a path to execute even when source files are not inspected. ReversingLabs also identified one compromised developer and observed attackers impersonating employees of major financial-services firms.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6a8b8bbd83ea4cfeaadaf397700f756… 2024-09-10 2024-09-10

Related Actors

Related Reports

« Back