supply-chain Rust Supply Chain Attack Linked to North Korean Hackers North Korean hackers, believed to be the Sapphire Sleet group, orchestrated a sophisticated supply chain attack targeting the Rust ecosystem. The attack leveraged a compromised Rust crate, arrayref, to deliver a malicious build script and a second-stage binary, ultimately aiming to compromise Rust projects across numer… SecurityWeek · Aug 21, 2026 High KPrustsupply chainnorth korean
threat-intel Trojanized npm Packages Decode C2 IP From Ethereum Recipient Addresses North Korean hackers are utilizing a new, more sophisticated command-and-control (C2) technique called NullReceiver to evade detection. Instead of embedding a C2 address in a transaction or using a smart contract, NullRe… The Hacker News · Aug 5, 2026 High KPc2ethereumnpm
threat-intel DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious co… The Hacker News · Jul 30, 2026 High KPmacosmalvertisingcrypto-stealer
threat-intel North Korea’s elite hackers turned on their own government – and got caught North Korea's elite hackers, trained by the Reconnaissance and Intelligence General Bureau (the same agency behind the Lazarus Group), turned their skills inward and attempted to steal funds from the country's two larges… Graham Cluley · Jul 30, 2026 High KPnorth koreahackingcybercrime
threat-intel Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet Amazon has attributed the September 2025 compromise of npm packages debug and chalk, along with subsequent incidents involving typo-crypto and axios, to North Korea’s Sapphire Sleet group. While initial reports attribute… The Hacker News · Jul 30, 2026 High KPnpmthreat intelligencemalware
threat-intel Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js Two compromised npm packages within the @joyfill namespace have been injected with a remote access trojan (RAT) linked to the DEV#POPPER malware family. These packages utilize a complex blockchain-based infrastructure (T… The Hacker News · Jul 29, 2026 High KPnpmmalwareremote access trojan
supply-chain New GitHub, PyPI Policies Boost Supply Chain Security GitHub and PyPI are implementing new policies to bolster supply chain security by delaying the adoption of newly released package versions and preventing the poisoning of older, stable releases. These measures aim to red… SecurityWeek · Jul 27, 2026 Medium KPsupply chainpackage managementsecurity
threat-intel BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery North Korean threat actors, operating under the BlueNoroff campaign, are using a sophisticated phishing kit to target crypto investors and venture capitalists. The kit leverages compromised trusted contacts and typosquat… The Hacker News · Jul 24, 2026 High KPphishingzoommicrosoft teams
threat-intel Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images North Korean threat actors, linked to the Contagious Interview campaign (REF9403), are using fake coding tests and SVG images containing steganography to deliver a multi-stage malware payload – OtterCookie – to software… The Hacker News · Jul 17, 2026 High KPsteganographysupply chaindeveloper
threat-intel North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This… The Hacker News · Jul 4, 2026 High KPnorth koreangithubmalware
threat-intel North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets North Korean-linked threat actors are deploying malicious npm packages that mimic Rollup polyfill tooling to steal developer secrets. These packages, including 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill… The Hacker News · Jul 3, 2026 High KPnpmthreat-actornorth korea
threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file
threat-intel New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis A new macOS malware, dubbed Gaslight, has been discovered using prompt injection techniques to deceive AI-powered analysis tools. Developed by North Korea-aligned threat actors, the malware steals information and attempt… The Hacker News · Jun 25, 2026 High KPmacosprompt injectionai evasion
supply-chain Microsoft links Mastra AI supply chain attack to North Korean hackers Microsoft has attributed a recent supply chain attack targeting over 140 npm packages to the North Korean hacking group Sapphire Sleet, also known as BlueNoroff. The attack involved compromising an npm maintainer account… BleepingComputer · Jun 20, 2026 High KPsupply-chainnpmcryptocurrency
threat-intel JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware A previously undocumented threat actor, dubbed JINX-0164, is targeting cryptocurrency firms through sophisticated social engineering tactics and bespoke macOS malware to steal digital assets. The campaign involves luring… The Hacker News · May 28, 2026 High KPmacossocial engineeringcryptocurrency
malware Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms The Lazarus Group, a North Korean threat actor, has deployed a new memory-only remote access trojan (RAT) called RemotePE to target financial and cryptocurrency firms. This multi-stage attack chain utilizes several loade… The Hacker News · May 25, 2026 High KPremote access trojannorth koreasocial engineering
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage