← BACK TO FEED
TAG

north korea5 articles

North Korean Hackers Poisoned One of Rust's Most Downloaded Packages

North Korean hackers, likely the group Sapphire Sleet, carried out a supply chain attack on the Rust ecosystem on August 20, compromising the widely-used *arrayref* crate by publishing a malicious version from its legitimate maintainer's hijacked account. The poisoned package contained a hidden build script designed to fetch a malicious second-stage binary, with the attack also spreading to several other related crates. The Rust Security Response Team removed all malicious packages within 86 minutes, found no evidence of actual usage, and linked the incident to previous North Korean-attributed NPM attacks based on shared infrastructure.

22 Aug 2026

AI Is Now Both the Weapon and the Bullseye: CrowdStrike's 2025 Threat Report Makes for Grim Reading

AI is increasingly being used as both an attack tool and a target, with AI-enabled cyberattacks rising 89% in 2025, according to CrowdStrike's annual Threat Hunting Report. Criminal groups and nation-state actors — most notably North Korea's Famous Chollima — are leveraging AI to launch sophisticated attacks, including credential theft, supply-chain compromises, and the creation of fake companies to support insider threat operations. AI is also accelerating vulnerability exploitation, with 88% of observed attacks using public proof-of-concept code occurring within 48 hours of release, effectively rendering traditional 30-day patching windows obsolete.

3 Aug 2026

North Korea's Contagious Interview Campaign Goes Full ClickFix With Blockchain C2

North Korea-linked threat actors have launched a sophisticated macOS malvertising campaign, dubbed a new iteration of "Contagious Interview," that redirects users to fake websites displaying a convincing full-screen fake software update to trick them into running malicious Terminal commands via the ClickFix technique. The malware uses "EtherHiding" — embedding C2 server addresses in Ethereum smart contracts — to resist takedowns, ultimately delivering an information stealer targeting 157 cryptocurrency wallets and a malicious Chrome extension designed to drain victims' funds. Notably, this campaign departs from the group's typical fake job interview lures, instead targeting ordinary web searches, suggesting North Korean operators are broadening their attack vectors beyond developer recruitment scenarios.

31 Jul 2026

North Korean Hackers Are Quietly Poisoning Open Source Repositories

North Korean hackers are conducting a supply chain campaign called PolinRider, active since December 2025, targeting open source developers across NPM, Packagist, Go modules, and Chrome extensions. The attackers compromise maintainer accounts to inject obfuscated JavaScript loaders into legitimate repositories, which deliver the DEV#POPPER RAT and OmniStealer malware, with 162 malicious artifacts identified across 108 packages so far. Security firm Socket warns that any developers who installed affected packages should treat their environment as potentially compromised and conduct remediation from a clean machine, as credentials for package registries, cloud services, and CI/CD pipelines may have been exposed.

12 Jul 2026

North Korean Hackers Hijack 108 Packages Across npm, Go and Chrome in Sprawling PolinRider Campaign

North Korean threat actors linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist, Go, and Google Chrome as part of an ongoing operation called PolinRider, which has compromised nearly 2,000 public GitHub repositories. The attackers use obfuscated JavaScript payloads, fake font files, and VS Code task files to deliver malware including BeaverTail, DEV#POPPER RAT, and OmniStealer, while rewriting Git history to make malicious changes appear legitimate and harder to detect. Developers are advised to treat any affected environments as fully compromised, rotate secrets, rebuild from clean lockfiles, and audit repositories for suspicious modifications to configuration files.

9 Jul 2026