Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Software Development Security - Lazarus Group Weaponizes Open Source in Global Espionage Campaign
Software Development Security Attacks Data Protection Latest News News & Analysis Security Threats and Vulnerabilities

Lazarus Group Weaponizes Open Source in Global Espionage Campaign

Kirsten DoyleBy Kirsten DoyleJuly 31, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Lazarus Group Weaponizes Open Source
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

An investigation from Sonatype has exposed a cyber-espionage campaign by North Korea’s infamous Lazarus Group, this time targeting the tools developers rely on every day.  

Between January and July 2025, Sonatype blocked 234 unique malware-laden packages across the npm and PyPI ecosystems; a calculated assault on the trust that underpins open-source software.

Disguised as popular developer utilities, these poisoned packages carried espionage implants designed to exfiltrate credentials, profile systems, and establish long-term backdoors. At last count, the campaign may have reached over 36,000 victims, and it’s still ongoing.

“Open source has become the new attack surface,” Sonatype warns. “It’s not just about code anymore. It’s about control.”

Nation-State Espionage in Your Dev Tools

The Lazarus Group, a long-standing arm of North Korea’s Reconnaissance General Bureau, has spent more than a decade honing its capabilities, from the Sony Pictures hack in 2014 to the WannaCry outbreak in 2017.

In 2025 alone, the group was linked to the $1.5 billion ByBit crypto theft. But recent activity suggests a strategic shift: from high-profile disruption to quiet, persistent infiltration.

And this time, they’re hiding in plain sight.

By injecting malware directly into open-source package registries, Lazarus is exploiting some hard truths about modern software development:

  • Most developers install packages without verification. 
  • CI/CD pipelines often propagate dependencies unchecked. 
  • Popular libraries may be maintained by just one or two volunteers. 
  • Developer environments contain API keys, tokens, and other secrets. 
  • Malicious code can sit dormant, until it doesn’t. 

It’s not just that developers are being targeted; their everyday workflows are being weaponized.

234 Packages, One Global Supply Chain

According to Sonatype’s telemetry, the compromised packages aped legitimate tools, sometimes by cloning known libraries with near-identical names, sometimes by impersonating trusted maintainers. The malware they delivered was precise, modular, and designed for stealth. 

Once installed, the implants quietly collected information and opened covert channels back to C2. The goal wasn’t a quick hit, but long-term access, the kind that allows adversaries to watch, learn, and wait for the right moment.

This isn’t the first time bad actors have targeted package registries, but the scale and sophistication of the Lazarus campaign ups the ante. It is a deliberate push into the heart of global software supply chains, where the line between trust and compromise is already wobbly. 

Sonatype Issues a Warning

Sonatype warns  that this is not a one-time event, it’s part of a trend. It’s a persistent threat that is not going away.

Sonatype’s full whitepaper, “How North Korea-Backed Lazarus Group Is Weaponizing Open Source”, provides a technical breakdown of the malware variants, the evolving tactics used by Lazarus, and guidance on how entities can defend themselves.

Exploiting Trust

Mike McGuire, senior software solutions manager at Black Duck, says: “Threat actors continue to exploit the inherent trust that is placed in the open-source community. While the overwhelming majority of open source projects are legitimate, it only takes one malicious package to poison the well.”

According to him, the recommended reaction to news like this requires that security teams prioritise application security without compromise. “This includes conducting a thorough analysis of the open-source dependencies used in their applications, ensuring none of them are identified to be known malicious components, whether they’re part of this Lazarus Group campaign, or any other attacker’s efforts. However, the most effective approach in preventing exposure to these types of attacks is to proactively evaluate dependencies for risk before using them. “ 

Enable Policy Enforcement

McGuire says teams should stand up private, internal repositories of vetted open-source packages, which can block malicious or suspicious packages before they reach development environments.

“They should also enable policy enforcement that can help avoid installing packages with unclear authorship or a low number of downloads. These policies can also help teams automatically prioritise well-maintained components with verified histories and trigger review workflows for suspicious components. Finally, teams should generate and review SBOMs regularly. This helps detect unauthorised or compromised dependencies and ensures visibility across all direct and transitive components in the software supply chain.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    AI-Powered Attacks Become Top Concern for Security Professionals, New Filigran Survey Reveals
  • Kirsten Doyle
    ShinyHunters targets Oracle PeopleSoft customers through critical zero-day
  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

SIG report: AI-generated code is linked to twice the security risk and rising technical debt

June 11, 20264 Mins Read

Closing the Cross-Platform Security Gap in Citizen Developer Apps

February 13, 20265 Mins Read

UK Businesses Hit by Wave of Breaches Caused by Insecure Code

August 19, 20253 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}