Jade Sleet

2023-07-18 • MicrosoftSecurity alert: social engineering campaign targe…

GitHub disclosed a low-volume social engineering campaign, publicly attributed with high confidence to a group it identified as Jade Sleet per Microsoft Threat Intelligence naming and TraderTraitor per CISA, that targeted personal accounts of technology-industry employees, primarily those connected to blockchain, cryptocurrency, and online gambling organizations, through fraudulent GitHub repository invitations paired with malicious npm package dependencies. Checkmarx subsequently confirmed the activity was tied to Jade Sleet, TraderTraitor, and the broader Lazarus Group, describing what it assessed as the first nation-state use of open-source supply chain infiltration: attackers built rapport with targets through fake developer and recruiter personas on LinkedIn, Slack, and Telegram before inviting them to collaborate on repositories containing paired first- and second-stage npm packages that were progressively refined with additional obfuscation and more robust error handling. Indicators from the campaign overlapped with the contemporaneous compromise of IT management firm JumpCloud, and the group used compromised developer trust and reputation to reach cryptocurrency and blockchain sector victims.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster