Lazarus Strikes npm Again with New Wave of Malicious Package

2025-03-10 Socket

https://socket.dev/blog/lazarus-strikes-npm-again-with-a-new-wave-of-malicious-packages

Thumbnail for Lazarus Strikes npm Again with New Wave of Malicious Package

North Korea’s Lazarus Group continues to infiltrate the npm ecosystem, deploying six new malicious packages designed to compromise developer environments, steal credentials, extract cryptocurrency data, and deploy a backdoor. The secondary payload (SHA256: 6a104f07ab6c5711b6bc8bf6ff956ab8cd597a388002a966e980c5ec9678b5b0 ) is downloaded under the filenames p.zi and extracted using tar -xf , following a multi-stage deployment strategy consistent with previous Lazarus campaigns that distributed the BeaverTail malware. Notably, the malware also targets cryptocurrency wallets, specifically extracting id.json from Solana and exodus.wallet from Exodus. In this campaign, Socket researchers uncovered BeaverTail malware embedded within seemingly benign packages — is-buffer-validator , event-handle-package , array-empty-validator , react-event-dependency , and auth-validator — each closely mirroring tactics previously documented in Lazarus (Contagious Interview) operations.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 172.86.84.38 2025-03-10 2025-11-13
HASH 6a104f07ab6c5711b6bc8bf6ff956ab… 2024-10-23 2025-07-26
EMAIL [email protected] 2025-03-10 2025-03-10
EMAIL [email protected] 2025-03-10 2025-03-10
EMAIL [email protected] 2025-03-10 2025-03-10
EMAIL [email protected] 2025-03-10 2025-03-10
EMAIL [email protected] 2025-03-10 2025-03-10
EMAIL [email protected] 2025-03-10 2025-03-10
DOMAIN softworldnet.com 2025-03-10 2025-03-10

Related Actors

Related Reports

2025-02-20 • 48% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: T1027.013, T1082, T1119 • Published within a month
« Back