Security News > 2024 > February > Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems
2024-02-29 08:17
The notorious North Korean state-backed hacking group Lazarus uploaded four packages to the Python Package Index (PyPI) repository with the goal of infecting developer systems with malware. The packages, now taken down, are pycryptoenv, pycryptoconf, quasarlib, and swapmempool. They have been collectively downloaded 3,269 times, with pycryptoconf accounting for the most
News URL
https://thehackernews.com/2024/02/lazarus-exploits-typos-to-sneak-pypi.html
Related news
- Hackers Exploit ConnectWise ScreenConnect Flaws to Deploy TODDLERSHARK Malware (source)
- Hackers exploit WordPress plugin flaw to infect 3,300 sites with malware (source)
- Malware Campaign Exploits Popup Builder WordPress Plugin to Infect 3,900+ Sites (source)
- Hackers exploit Windows SmartScreen flaw to drop DarkGate malware (source)
- Fujitsu found malware on several systems, confirms data breach (source)
- Fujitsu found malware on IT systems, confirms data breach (source)
- Fujitsu finds malware on company systems, investigates possible data breach (source)
- Fujitsu: Miscreants infected our systems with malware, may have stolen customer info (source)
- SoumniBot malware exploits Android bugs to evade detection (source)
- CoralRaider Malware Campaign Exploits CDN Cache to Spread Info-Stealers (source)