Toutes les vulnérabilités
HIGHSupply chainexploited in the wild

NPM-LAZARUS-CONTAGIOUS-INTERVIEW-2024

npm · Lazarus 'Contagious Interview' malicious packages (campaign)

Résumé

An ongoing North Korean Lazarus Group campaign (publicly detailed in 2024, dubbed 'Contagious Interview'/Wagemole) plants malicious typosquat and lookalike packages on npm to target cryptocurrency and Web3 developers. Operators pose as recruiters on LinkedIn and other platforms, luring developers into running malicious packages as part of fake coding interviews. The packages steal account credentials, deploy backdoors (BeaverTail/InvisibleFerret malware families) and extract cryptocurrency wallet data; one identified set of six packages was downloaded around 330 times. The campaign has continued through 2025 with fresh package waves.

Références

Vulnérabilités liées

Tout Supply chain →