The Lazarus group from North Korea uses malicious npm packages to steal data. Six packages, such as is-buffer-validator and auth-validator, have been downloaded more than 300 times and employed a technique called typesquatting. These packages target credentials and information from Solana and Exodus cryptocurrency wallets, as well as data from Chrome, Brave, and Firefox browsers. The infected data is sent to a C2 server. Lazarus has previously conducted similar attacks, including the Bybit hack, which resulted in the theft of $1.46 billion.
3/12/2025 11:06:00 AM (GMT+1)
The Lazarus group from North Korea uses malicious npm packages to steal cryptocurrency and developer data, including information from Solana and Exodus wallets


This material was prepared by Khachatur Davtyan, developed and translated by artificial intelligence.