#VMConnect

Incident/Operation

2023-08-03 • VMConnect: Malicious PyPI packages imitate popular open source modules

VMConnect is a DPRK-linked software supply-chain and social-engineering campaign first identified in July–August 2023 and tied by researchers to Lazarus Group. It initially published malicious PyPI packages that closely imitated popular Python tools and concealed downloader code, then evolved into fake recruiter approaches and time-pressured coding tests hosted in convincing repositories. The embedded Python modules used obfuscation, executed system commands, wrote and ran local files, and exfiltrated data, targeting software developers under the guise of employment with major financial firms.

Tagged Reports

« Back