Researchers have reportedly discovered a highly advanced operation from North Korea that’s sneaking crypto-stealing malware into open-source software. The stealthy campaign is designed to spread malware, putting unsuspecting users at risk.
In a blog post published on Thursday (Feb. 13), STRIKE analysts from SecurityScorecard said that North Korea’s Lazarus Group was spreading “undetectable” malicious code through GitHub and NPM packages via Operation Marstech Mayhem. The team also added on X: “Developers are unknowingly pulling infected repositories into their projects, putting crypto wallets and software supply chains at risk.”