Security News > 2023 > August > Lazarus hackers deploy fake VMware PyPI packages in VMConnect attacks

Lazarus hackers deploy fake VMware PyPI packages in VMConnect attacks
2023-08-31 18:47

North Korean state-sponsored hackers have uploaded malicious packages to the PyPI repository, camouflaging one of them as a VMware vSphere connector module named vConnector.

The packages were uploaded at the beginning of August, with one named VMConnect targeting IT professionals seeking virtualization tools.

A report today from ReversingLabs, a software supply chain security company, attributes the campaign to Labyrinth Chollima, a subgroup of North Korean Lazarus hackers.

The researchers discovered more packages that are part of the same VMConnect operation, namely 'tablediter', 'request-plus', and 'requestspro'.

FBI: Lazarus hackers readying to cash out $41 million in stolen crypto.

Fake VMware vConnector package on PyPI targets IT pros.


News URL

https://www.bleepingcomputer.com/news/security/lazarus-hackers-deploy-fake-vmware-pypi-packages-in-vmconnect-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 146 11 222 256 102 591
Pypi 15 0 0 1 15 16