Wednesday, September 16, 2026
Follow on LinkedIn

Lazarus Adds New Malicious npm Packages with Hexadecimal Encoding to Evade Detection

The Lazarus Group, a notorious North Korean state-sponsored hacking collective, has escalated its cyber warfare tactics by introducing new malicious npm packages with advanced obfuscation techniques.

These packages, part of the broader Contagious Interview operation, are designed to evade automated detection systems and manual code audits, marking a significant evolution in the group’s approach to cyber espionage and financial theft.

The latest campaign has seen the Lazarus Group expand its presence in the npm ecosystem, publishing packages under new aliases like taras_lakhai, mvitalii, wishorn, and crouch626.

These packages, which include utilities for arrays, logging, debugging, and event handling, have been downloaded over 5,600 times before their suspension from the npm registry.

The packages employ hexadecimal string encoding to hide critical strings such as function names, URLs, and command and control (C2) server addresses, making them less detectable during static analysis.

Obfuscation Techniques

The obfuscation strategy involves encoding strings in hexadecimal format, which are then decoded at runtime using JavaScript’s String.fromCharCode function reads the Socket report.

This method effectively conceals the true functionality of the malware, allowing it to bypass both automated scanners and manual code reviews. For instance, the package cln-logger uses this technique to decode strings like “require,” “axios,” and “get,” which are essential for fetching and executing code from C2 servers.

The threat actors have shown a consistent pattern in their infrastructure usage. For example, the accounts taras_lakhai and mvitalii connect to the same C2 server at 45.61.151[.]71 on port 1224, indicating a coordinated effort.

Application Security is no longer just a defensive play, Time to Secure -> Free Webinar

Similarly, the wishorn account uses an obfuscated C2 IP address within its packages, linking it directly to known Lazarus infrastructure.

These packages share not only common C2 endpoints but also exhibit structural similarities with previously attributed Lazarus operations, including the use of BeaverTail, an infostealer targeting browser data, macOS keychain, and cryptocurrency wallets.

In a strategic move to legitimize their operations, the Lazarus Group has shifted from GitHub to Bitbucket for hosting their malicious code.

Code Hosting

This transition was observed with packages like events-utils and icloud-cod, which were linked to Bitbucket repositories before their npm publication. This sequencing likely aims to give the packages an appearance of active maintenance and legitimacy, potentially deceiving developers into trusting these packages.

Given the persistent and evolving nature of these attacks, organizations are urged to enhance their software supply chain security. This includes implementing automated dependency audits, contextual scanning of third-party packages, and monitoring for unusual dependency changes.

Blocking outbound traffic to known or suspicious C2 endpoints is also crucial. Tools like Socket’s GitHub App, CLI, and browser extension are recommended to detect and prevent such threats proactively.

The Lazarus Group’s latest campaign underscores the group’s adaptability and persistence in targeting software supply chains. With their use of advanced obfuscation techniques and a shift in hosting strategies, they continue to pose a significant threat to developers and organizations worldwide.

As these cyber threats evolve, so must the defensive strategies of those in the software development community, ensuring that security is not just an afterthought but a fundamental aspect of the development process.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try 50 Request for Free

Guru Baran
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Cyber Security Guide

Latest Cyber News

Expert Talks