July 21, 2023, 5:10 p.m. | SC Staff

SC Magazine feed for Threats www.scmagazine.com

Malicious NPM package dependencies and repository invitations have been leveraged by North Korean state-backed hacking operation Lazarus Group, also known as TraderTraitor and Jade Sleet, in limited social engineering attacks against cybersecurity, cryptocurrency, blockchain, and online gambling developers in GitHub, reports BleepingComputer.

attacks bleepingcomputer blockchain campaign cryptocurrency cybersecurity dependencies developers engineering gambling github hacking lazarus lazarus group malicious malicious npm north north korean npm npm package package reports repository social social engineering social engineering attacks state threat management tradertraitor vulnerability management

Incident Response Lead

@ Blue Yonder | Hyderabad

GRC Analyst

@ Chubb | Malaysia

Information Security Manager

@ Walbec Group | Waukesha, WI, United States

Senior Executive / Manager, Security Ops (TSSQ)

@ SMRT Corporation Ltd | Singapore, SG

Senior Engineer, Cybersecurity

@ Sonova Group | Valencia (CA), United States

Consultant (Multiple Positions Available)

@ Atos | Plano, TX, US, 75093