threat-intel DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware North Korean-linked threat actors are using a sophisticated macOS malvertising campaign to deliver crypto-stealing malware. The campaign mimics a fake software update sequence to trick users into executing a malicious command via the Terminal app, ultimately installing a Node.js backdoor that harvests cryptocurrency wa… The Hacker News · Jul 30, 2026 High KPmacosmalvertisingcrypto-stealer