National Cyber Warfare Foundation (NCWF) Forums


Fake recruiter coding tests target devs with malicious Python packages


0 user ratings
2024-09-10 12:43:20
milo
Developers

ReversingLabs researchers have identified new, malicious software packages believe to be linked to a campaign, VMConnect, that our team first identified in August 2023 and which has ties to the North Korean hacking team Lazarus Group. The new samples were tracked to GitHub projects that have been linked to previous, targeted attacks in which developers are lured using fake job interviews. Furthermore, information gathered from the detected samples allowed us to identify one compromised developer and provided insights into an ongoing campaign, with attackers posing as employees of major financial services firms.


The post Fake recruiter coding tests target devs with malicious Python packages appeared first on Security Boulevard.



Karlo Zanki

Source: Security Boulevard
Source Link: https://securityboulevard.com/2024/09/fake-recruiter-coding-tests-target-devs-with-malicious-python-packages/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers



Copyright 2012 through 2024 - National Cyber Warfare Foundation - All rights reserved worldwide.