GitHub is warning about a social engineering campaign by hackers Lazarus , targeting the accounts of developers in the blockchain, cryptocurrencyand cybersecurity , online gambling , sectors . The campaign aims to infect developers' devices with malware.

The Lazarus group has a long history of targeting cryptocurrency companies and cybersecurity researchers. Their goal is to steal cryptocurrency and cyberespionage.
Targeting developers with malware
In a new security alert, GitHub warns that the Lazarus group is hacking legitimate accounts or creating fake personas, purporting to be developers and recruiters on GitHub and social media.
According to the alert, GitHub detected the social engineering (targeting the personal accounts of tech company employees) “using a combination of repository invitations and malicious npm package dependencies.”
See also: Fake PoC for a Linux Kernel vulnerability on GitHub contains malware
Hacked and fake accounts are used to reach out and initiate conversations with developers and employees in the cryptocurrency, online gambling, and cybersecurity industries .These conversations usually lead to another platform (e.g., WhatsApp).
After establishing a climate of trust, Lazarus hackers invite developers to collaborate with them on a project and clone a GitHub repository on the subject of media players and cryptocurrency.
However, GitHub says that these projects use malicious NPM dependencies that download further malware to the targets’ devices. According to GitHub, these malicious NPMs act as a first-stage malware downloader. A recent report by Phylum provides more details about the malicious NPMs.
According to Phylum, NPMs act as malware that connect to remote websites to execute additional payloads on the infected machine.
Unfortunately, Phylum researchers were unable to obtain the second-stage payloads to see the final malware and its behavior on the target device.
See also: Fake zero-day PoC exploits on GitHub spread Windows and Linux malware

GitHub says it has suspended all NPM and GitHub accounts and published a full list of domains, GitHub accounts , and NPM packages associated with the social engineering campaign.
The company also emphasizes that no GitHub or npm systems were compromised during this campaign.
We have seen similar campaigns from Lazarus hackers before. For example, in January 2021, hackers targeted security researchers by creating fake social media that purported to be “security researchers.”
A similar campaign was conducted in March 2021, when hackers created a website for a fake company called SecuriElite to infect researchers with malware.
North Korean hackers have a long history of targeting companies and developers involved in crypto.
See also: How to download GitHub Desktop on Windows 10/11?
The Lazarus hackers have become known worldwide for their attacks. The events of recent years have shown that they pose a significant threat to global cybersecurity. The most vulnerable targets are private organizations , state-owned industries, and individuals. Attack prevention and protection measures are essential to protect against the group's operations. As for the protection of developers, it is important to thoroughly check the projects they decide to use, verifying the origin and reliability of the contributors. Strong antivirus software and a firewall, with regular updates, are also recommended to ensure strong protection against potential threats .
Source: www.bleepingcomputer.com
