Lazarus Group Launches First Open Source Supply Chain Attacks Targeting Crypto Sector

2023-08-02 Checkmarx

https://medium.com/checkmarx-security/lazarus-group-launches-first-open-source-supply-chain-attacks-targeting-crypto-sector-cabc626e404e

Thumbnail for Lazarus Group Launches First Open Source Supply Chain Attacks Targeting Crypto Sector

Checkmarx reported a Lazarus/Jade Sleet/TraderTraitor campaign targeting blockchain, cryptocurrency, and online gambling organizations through malicious npm package dependencies. The attackers used fake developer and recruiter personas on platforms such as LinkedIn, Slack, Telegram, and GitHub to persuade targets to collaborate on repositories containing paired malicious packages. The first package created a hidden .svnlook directory and fetched update data from cryptopriceoffer.com, while the second read the token, requested a follow-on payload, wrote it to disk, and executed it with Node.js; both disabled TLS certificate verification. The report frames this as a nation-state open-source supply-chain intrusion and notes the actor refined package synchronization and encoding over time to reduce detection.

Indicators of Compromise

Type Value First Seen Last Seen
YARA lazarus_2 2023-08-02 2023-08-02
YARA lazarus_1 2023-08-02 2023-08-02
URL https://cryptopriceoffer.com/ch… 2023-08-02 2023-08-02
DOMAIN npmaudit.com 2023-07-18 2023-08-02
DOMAIN cryptopriceoffer.com 2023-07-18 2023-08-02
DOMAIN coingeckoprice.com 2023-07-18 2023-08-02
DOMAIN npmjscloud.com 2023-07-18 2023-08-02
DOMAIN tradingprice.net 2023-06-23 2023-08-02
DOMAIN npmrepos.com 2023-06-23 2023-08-02
DOMAIN npmcloudjs.com 2023-06-23 2023-08-02
DOMAIN bi2price.com 2023-06-23 2023-08-02
DOMAIN npmjsregister.com 2023-06-23 2023-08-02

Related Actors

Related Reports

« Back