North Korean threat actors are back - and scaling up. The #Lazarus Group is expanding its npm malware campaign with new RAT loaders, hex obfuscation, fresh aliases, and over 5,600 downloads across 11 packages.
Our latest research: https://socket.dev/blog/lazarus-expands-malicious-npm-campaign-11-new-packages-add-malware-loaders-and-bitbucket #JavaScript #malware
All of these are coming out within the next week!
#Iyanu #Lazarus #SouthOfMidnight
https://mastodon.online/@cynicalelysian/114113397695379234
Geekly Weekly Sunday Digest #299
March 23rd - 29th
A weekly Pop Culture Ranking
Full lists at http://www.99geek.ca
Subscribe for free to get it in your email!
NEW RELEASES PERSONAL RANKING
#Daredevil
#ThePitt
#FamilyGuy
#WheelOfTime
#Krapopolis
#TheEqualizer
#SaturdayNightLive
#StDenisMedical
#SonofaCritch
#TheStudio
#MidCenturyModern
NEXT WEEK
#Minecraft
#DyingForSex
#WilliamTell
#Mobland
#DevilMayCry
#FreakyTales
#Lazarus
#Pulse
#JurassicWorld
#Bondsman
#WakeUp
Or had the cynics laughed and only yawned?
Afterlife
Royal Rhodes
No subbed airings alongside the dubs for #Lazarus, huh? This will be the first #Toonami Original anime since #HousingComplexC to not have the sub airing at the same time as the dub.
I feel completely in love with Love and Rockets by the Hernandez brothers in the 80s. After the first 50 issues they took a long break and I lost track, but started catching up again about 15 years ago or so. Then I lost track again.
But I miss these amazing stories, so this year is when I start buying all the trades and read the whole thing from the start.
I'll also be catching up with Saga and Lazarus and more. It'll be fun.
Kończę właśnie "Wielki skok Grupy Lazarus" autorstwa Geoffa White'a i jest to naprawdę dobra książka, tylko denerwuje mnie niepomiernie używanie przez tłumaczkę słowa "wirus" jako odpowiednika angielskiego "malware". Ja wiem, że "złośliwe oprogramowanie" nie jest zbyt poręcznym terminem, ale naprawdę nie wszystko, co atakujący wpuszczają do sieci, można nazwać wirusem. To nie są synonimy
#NorthKorea's #Lazarus hackers infect hundreds via #npm packages
Six malicious packages have been identified on npm.The packages, which have been downloaded 330 times, are designed to steal account credentials, deploy backdoors on compromised systems, and extract sensitive cryptocurrency information.
Threat group is known for pushing malicious packages into software registries like npm which is used by millions of JavaScript developers, and compromising systems passively.
https://www.bleepingcomputer.com/news/security/north-korean-lazarus-hackers-infect-hundreds-via-npm-packages/
The Socket Research Team has uncovered 6 new malicious npm packages linked to North Korea’s #Lazarus Group. These packages steal credentials, extract crypto data, and deploy backdoors.
Read the full report: https://socket.dev/blog/lazarus-strikes-npm-again-with-a-new-wave-of-malicious-packages #NodeJS #cybersecurity #malware
#BBCNews - North Korean hackers cash out hundreds of millions from $1.5bn ByBit hack
https://www.bbc.com/news/articles/c2kgndwwd7lo
#Lazarus