MAL-2023-1549
Dashboard / Malicious Package / MAL-2023-1549
MAL-2023-1549
Summary: Malicious code in binance-price (npm)
Details: Source: checkmarx (421081a4101ed61796fd72e7dec62cafa098a1d01934298a2ef82ef7187c4934) Lazarus Group targeting blockchain and cryptocurrency companies by exploiting software supply chains through malicious npm packages and social engineering tactics
References: https://medium.com/checkmarx-security/lazarus-group-launches-first-open-source-supply-chain-attacks-targeting-crypto-sector-cabc626e404e, https://blog.phylum.io/junes-sophisticated-npm-attack-attributed-to-north-korea/, https://security.snyk.io/vuln/SNYK-JS-BINANCEPRICE-5803117
Affected packages
Package
Name: binance-price
Purl: pkg:npm/binance-price
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
1.6.1
