How Lazarus Group Uses Open Source to Attack Developers | Webinar

How Lazarus Group Uses Open Source to Attack Developers

Watch Now

Open source has become a primary target for sophisticated threat actors, including the North Korea-linked Lazarus Group. This webinar examines how nation-state attackers exploit developer ecosystems by distributing malicious code through widely used package repositories such as npm and PyPI. Gain insight into the tactics used in these supply chain attacks and learn practical strategies for mitigating your risk.

The Lazarus Group — an advanced persistent threat (APT) linked to North Korea — is weaponizing the trust inherent in open source ecosystems like npm and PyPI. Sonatype’s latest research uncovered 234 unique malware packages attributed to Lazarus in the first half of 2025 alone, representing 36,000 potential victims. This on-demand webinar exposes how Lazarus Group is turning open source into a delivery mechanism for cyberespionage.

Learn how these malicious actors exploit developers’ trust, deploy multi-stage malware, and use sophisticated obfuscation to evade detection.

Key Takeaways

This webinar equips you with the knowledge and strategies needed to mitigate the rising threat of supply chain attacks. Enable your teams to stay secure without sacrificing speed or innovation.

Featured Speakers

Bruce Mayhew

VP, Data Engineering, Sonatype

Garrett Calpouzos

Principal Security Researcher, Sonatype