News

Lazarus Group Uses npm Brandjacking Campaign to Target Developers

  • Waqas--HackRead
  • published date: 2026-06-04 12:35:11 UTC

North Korean Lazarus Group targets npm developers with brandjacking packages that mimic trusted tools, drop malware and put credentials at risk.

A new npm campaign linked to North Koreas Lazarus Group shows how attackers are using familiar-looking package names to gain access to developers systems and software build environments. Sonatype Se… [+3558 chars]