lastweek.lazarus.day

Last Week in DPRK Cyber

A weekly briefing on DPRK state-sponsored cyber threat activity, tracked using lazarus.day.
Written and curated with AI.

Read the latest issue →

LW32: AI adoption, developer compromise, and IT worker exposure

Executive Summary

Last week’s reporting covered DPRK activity against developers, software supply chains, and remote hiring. Genians found Kimsuky infrastructure running local AI tools and document retrieval software. CrowdStrike attributed the poisoning of 131 AI framework packages to STARDUST CHOLLIMA, while an investigation into North Korean command-and-control servers found evidence of intrusions at hundreds of organizations.

LW31: Package compromise, watering holes, and developer-led theft

Executive Summary

Last week’s DPRK-related reporting focused on open-source compromise, blockchain-based command delivery, and attacks through trusted South Korean websites and security software. Supply-chain campaigns first compromised developers or maintainers, then pushed malicious code into legitimate npm packages and Go modules. Separate research documented APT37’s NarwhalRAT infrastructure and an AFX bridge theft attributed in a detailed post-mortem to UNC4899 / TraderTraitor.

LW29: Developer access, package spread, and IT worker infrastructure

Executive Summary

Last week’s reporting joined two risks that often begin with developer access. Fake coding tests delivered cross-platform credential theft, while stolen developer accounts and package publishing access spread malicious code through GitHub and npm. PolinRider’s confirmed footprint rose to 4,367 repositories, and separate research connected the ChainVeil and ViteVenom package clusters to the same campaign with differing attribution confidence.

LW28: PolinRider expansion, cross-chain laundering, and RokRAT delivery

Executive Summary

Last week’s reporting covered developer ecosystem compromise, digital-asset theft and laundering, and an APT37 RokRAT campaign. PolinRider expanded from npm into Go modules, Packagist packages, and Chrome extensions. The reporting tied that expansion to compromised GitHub accounts and repository release paths, putting source-control identity at the center of package security.

LW26: Managed IT worker operations, macOS intrusion, and blockchain dead drops

Executive Summary

Last week’s reporting covered several routes into developer and financial environments. Internal records obtained by the BBC described a managed DPRK IT worker operation built around borrowed identities, assigned roles, close supervision, and foreign-currency quotas. Malware research documented memory-resident Windows tooling, macOS surveillance implants, malicious npm packages, and Kimsuky phishing chains.

LW25: Mastra npm compromise, developer lures, and crypto custody failures

Executive Summary

Last week’s reporting centered on developer access as a route into software supply chains and cryptocurrency systems. The Mastra incident put that risk into production at scale: a compromised maintainer account added easy-day-js to more than 140 npm packages, exposing developer workstations and CI runners to a cross-platform Node.js implant. Other reports described malicious code hidden in configuration files, blockchain-based payload resolution, fake interviews, and poisoned packages.

LW24: Signer theft, malicious pull requests, and phishing RATs

Executive Summary

The Humanity Protocol $H compromise was the clearest incident last week. A phishing attachment led to remote access on a director’s Windows endpoint, theft of wallet and signer material, changes to bridge and contract authority, unauthorized minting, and token sales. The incident joined endpoint security directly to protocol governance and market impact.