-= Per source details. Do not edit below this line.=-
Lazarus Group targeting blockchain and cryptocurrency companies by exploiting software supply chains through malicious npm packages and social engineering tactics
{
"iocs": {
"domains": [
"cryptopriceoffer.com",
"npmjscloud.com",
"npmrepos.com",
"tradingprice.net",
"npmjsregister.com",
"npmcloudjs.com",
"bi2price.com",
"npmaudit.com",
"coingeckoprice.com"
]
},
"malicious-packages-origins": [
{
"import_time": "2023-08-23T13:55:32.289722419Z",
"modified_time": "2023-08-21T20:12:58Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "SEMVER"
}
],
"sha256": "06ba52961b5d886349fdb5a7c3e6362cedaaa64cb5857d5645d7360a68d133d1",
"source": "checkmarx"
},
{
"id": "RLMA-2024-00610",
"import_time": "2024-06-28T02:42:26.327186637Z",
"modified_time": "2024-06-25T12:33:51Z",
"sha256": "74c8ae80a6d42babd3ed8657c2c956c08fc764c7384bbd4e636b7749abb67257",
"source": "reversing-labs",
"versions": [
"3.2.12",
"3.2.13"
]
}
]
}