Skip to content
supplychainattack.orgSupply chain attack incident catalog

Lazarus Group supply chain incidents

North Korea-linked operation publicly attributed to multiple supply chain compromises, including the 3CX desktop app compromise and recurring malicious npm and PyPI package campaigns targeting developers.

Also tracked as: Lazarus, Hidden Cobra, APT38, Diamond Sleet, ZINC

1 confirmed incident publicly associated with this group. Attribution reflects what the cited sources state; it is recorded for filtering, not asserted by this site.

  1. resolvedhigh

    Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers

    Amazon attributed multiple high-profile npm supply chain attacks targeting the Debug and Chalk packages to North Korean threat actors. The incidents involved compromised packages in the npm ecosystem with significant downstream impact.

    Lazarus GroupnpmCompromised packageMalicious maintainer