How North Korea-Backed Lazarus Group Is Weaponizing Open Source to Target Developers

2025-07-31 Sonatype

https://www.sonatype.com/resources/whitepapers/how-lazarus-group-is-weaponizing-open-source

Attachments

How-North-Korea-Backed-Lazarus-Group-is-Weaponizing-Open-Source-Whitepaper.pdf (8 MB)

Thumbnail for How North Korea-Backed Lazarus Group Is Weaponizing Open Source to Target Developers

Sonatype reports that the North Korea-backed Lazarus Group is abusing open source package ecosystems as part of a strategic software supply-chain campaign. In the first half of 2025, Sonatype’s automated detection identified 234 unique malware packages in open source registries attributed to Lazarus and aimed at software engineers, CI/CD pipelines, and developer environments. The campaign uses npm and PyPI package trust to impersonate legitimate components and deliver multi-stage malware capable of clipboard stealing, credential harvesting, file theft, Windows keylogging, secret exfiltration, and longer-term access. The report highlights a shift toward compromising developer workflows and SDLC infrastructure rather than simply targeting end users or mining cryptocurrency.

Related Actors

Related Reports

2025-08-25 • 53% Match
#Lazarus #GolangGhost #T1059.003 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1071.001 #T1115 #T1083 #T1056.001 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1497.001 #T1219 #T1574.002 #T1562.001 #T1622 #T1027.002 #T1573.001 #T1190 #T1123 #T1132.002 #T1564.001 #T1548.002 #T1055.012 #T1027.007 #T1217 #T1106 #T1027.009 #T1036.003 #T1055.002 #T1036.007 #T1059.010 #T1136.001 #T1134.004 #T1614.001 #T1574.007 #T1098.007 #T1010 #T1071.004 #T1021.002 #T1021.006
Shares tag: Lazarus • Published within a month
« Back