Cybersecurity researchers have identified a new set of malicious Python packages that target software developers, pretending to offer coding tests.

“The new samples were tracked to GitHub projects related to previous targeted attacks, where developers were lured in via fake job offers,” said ReversingLabs researcher Karlo Zanki. This activity has been assessed as part of an ongoing malicious campaign called VMConnect, which first appeared in August 2023. There is evidence linking it to the hacking group Lazarus, which is based in North Korea.
See also: Mustang Panda uses PUBLOAD and HIUPAN malware in attacks
The use of fake job offers as a means of infection has become widely known by North Korean threat actors, who approach unsuspecting developers on platforms like LinkedIn or trick them into downloading suspicious packages as part of supposed skills tests.
These packages have been published directly to public repositories like npm and PyPI, or hosted on GitHub repositories controlled by them.
ReversingLabs announced the discovery of malicious code embedded in modified versions of legitimate PyPI libraries, such as pyperclip and pyrebase.
“The malicious code is located in both the init.py file and the corresponding compiled Python file (PYC) in the pycache of the relevant modules,” Zanki said.
It is implemented as a Base64 encoded string that hides a receive operation. This operation establishes a connection to a command and control (C2) server to execute commands received in response.
In one coding assignment case identified by a software supply chain company, threat actors attempted to create a false sense of urgency by requiring prospective employees to deliver a shared Python project in ZIP file format within five minutes and to identify and fix a coding error within 15 minutes.
Read more: North Korean hackers distribute COVERTCATCH malware
This makes it “more likely to execute the package without any prior security checks or source code evaluation,” Zanki said, adding that “this ensures the malicious actors behind this hacking group that the embedded malware will execute on the developer’s system.”
Some of the tests above are said to be technical interviews for financial institutions such as Capital One and Rookery Capital Limited. They highlight how threats mimic legitimate industry companies to enable their operations.
It's unclear at this time how widespread these campaigns are, but as Mandiant , a Google company , recently highlighted, potential targets are being sought out via LinkedIn.
"After an initial conversation, the hacker sends a ZIP file containing COVERTCATCH malware, disguised as a problem in Python coding. This file compromises the user's macOS system by downloading a second malware that persists on the system via Launch Agents and Launch Daemons," the company said.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Cybersecurity firm Genians has revealed that a North Korean malicious actor codenamed Konni is stepping up its attacks against Russia and South Korea. It is using spear-phishing that leads to the deployment of AsyncRAT, with overlaps related to a malicious campaign called CLOUD#REVERSER (also known as punK-002).
See more: SpyAgent: New Android malware steals crypto wallet recovery phrases
Some of these attacks include the spread of a new malware called CURKON. It is a Windows shortcut (LNK) file that acts as a downloader for a variant of the Lilith RAT using AutoIt. This activity has been linked to a subcluster tracked as puNK-003, according to S2W.
Source: thehackernews
