Six malicious packages were detected in npm (Node Package Manager), linked to the notorious North Korean hacking group Lazarus.
See also: Lazarus linked to $1.5 billion ByBit heist

The packages, which have been downloaded 330 times, are designed to steal credentials , deploy backdoors on compromised systems, and extract sensitive cryptocurrency information.
The Socket research team discovered the campaign, which linked it to previously known Lazarus supply chain operations.
The hacking group is known for pushing malicious packages to software repositories like npm, which is used by millions of JavaScript, and for passively compromising systems. Similar campaigns attributed to the same malicious actors have been spotted on GitHub and the Python Package Index (PyPI). This tactic often allows them to gain initial access to valuable networks and carry out record-breaking mass attacks, such as the recent $1.5 billion from Bybit.
The six Lazarus packages discovered on npm all use typosquatting to trick developers into random installs:
- is-buffer-validator – Malicious package that mimics the popular is-buffer library for credential theft.
- yoojae-validator – Fake validation library used to extract sensitive data from infected systems.
- event-handle-package – Disguised as an event handler, but deploys a backdoor for remote access.
- array-empty-validator – A rogue package designed to collect system and browser credentials.
- react-event-dependency – It presents itself as a React utility but runs malware to compromise developer environments.
- auth-validator – Mimics authentication validation tools to steal login credentials and API keys.
See also: Operation 99: Lazarus hackers target Web3 developers

The packages contain malicious code designed to steal sensitive information, such as cryptocurrency wallets and browser data containing saved passwords, cookies, and browsing history.
They also load the BeaverTail malware and the InvisibleFerret backdoor , which North Korean hackers previously deployed in fake job offers that led to the installation of malware.
All six Lazarus packages are still available in the npm and GitHub, so the threat is still active.
It is recommended that software developers double-check the packages they use for their projects and constantly audit the code in open source software to find suspicious signs such as obfuscated code and calls to external servers.
See also: Lazarus exploits zero-day in Chrome for attacks
Malware campaigns are coordinated efforts by cybercriminals or threat actors to spread malicious software (malware) across multiple systems or networks with the goal of stealing sensitive information, disrupting operations, or exploiting systems for various malicious purposes. These campaigns are often carried out through different actors and can include various types of malware, such as viruses, ransomware, spyware, adware, trojans, and more. Malware campaigns are constantly evolving, with attackers adopting new tactics, tools, and methods to evade detection and maximize their impact. It is important to remain vigilant and adopt a proactive security posture to reduce the risk posed by these malicious attempts.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
