MAL-2023-1550
Dashboard / Malicious Package / MAL-2023-1550
MAL-2023-1550
Summary: Malicious code in btc-api-node (npm)
Details: Source: checkmarx (f59f6e40fe31bd4d5d4aa5da8bc0d032e2bbff9166104dc707c2987f953a5d93) Lazarus Group targeting blockchain and cryptocurrency companies by exploiting software supply chains through malicious npm packages and social engineering tactics
References: https://medium.com/checkmarx-security/lazarus-group-launches-first-open-source-supply-chain-attacks-targeting-crypto-sector-cabc626e404e, https://security.snyk.io/vuln/SNYK-JS-BTCAPINODE-5803116, https://www.reversinglabs.com/blog/more-malicious-npm-packages-found-in-wake-of-jumpcloud-supply-chain-hack, https://blog.phylum.io/junes-sophisticated-npm-attack-attributed-to-north-korea
Affected packages
Package
Name: btc-api-node
Purl: pkg:npm/btc-api-node
Affected ranges
Type: SEMVER
Events:
