Lazarus Group Launches First Open Source Supply Chain Attacks Targeting Crypto Sector
2023-08-02 • Checkmarx •
Checkmarx reported a Lazarus/Jade Sleet/TraderTraitor campaign targeting blockchain, cryptocurrency, and online gambling organizations through malicious npm package dependencies. The attackers used fake developer and recruiter personas on platforms such as LinkedIn, Slack, Telegram, and GitHub to persuade targets to collaborate on repositories containing paired malicious packages. The first package created a hidden .svnlook directory and fetched update data from cryptopriceoffer.com, while the second read the token, requested a follow-on payload, wrote it to disk, and executed it with Node.js; both disabled TLS certificate verification. The report frames this as a nation-state open-source supply-chain intrusion and notes the actor refined package synchronization and encoding over time to reduce detection.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | lazarus_2 | 2023-08-02 | 2023-08-02 |
| YARA | lazarus_1 | 2023-08-02 | 2023-08-02 |
| URL | https://cryptopriceoffer.com/ch… | 2023-08-02 | 2023-08-02 |
| DOMAIN | npmaudit.com | 2023-07-18 | 2023-08-02 |
| DOMAIN | cryptopriceoffer.com | 2023-07-18 | 2023-08-02 |
| DOMAIN | coingeckoprice.com | 2023-07-18 | 2023-08-02 |
| DOMAIN | npmjscloud.com | 2023-07-18 | 2023-08-02 |
| DOMAIN | tradingprice.net | 2023-06-23 | 2023-08-02 |
| DOMAIN | npmrepos.com | 2023-06-23 | 2023-08-02 |
| DOMAIN | npmcloudjs.com | 2023-06-23 | 2023-08-02 |
| DOMAIN | bi2price.com | 2023-06-23 | 2023-08-02 |
| DOMAIN | npmjsregister.com | 2023-06-23 | 2023-08-02 |