2026-08
Between August 29 and September 2, 2026, attackers using a compromised collaborator account force-pushed a forged merge commit across 20 BindsNET GitHub branches, and a routine Dependabot merge carried the malicious files into the master branch. Opening a…
#SupplyChain
#Technology
2026-08
On August 20, 2026, attackers used a compromised crates.io maintainer account to publish malicious versions of arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 that pulled the typosquatted proc-macro1 build-time dropper. Building an affected R…
#SupplyChain
#Technology
2026-07
Operation DoubleBarrel links a state-sponsored intrusion set and the Gunra ransomware group through overlapping attacks against South Korean citizens and organizations from 2025 through the first half of 2026. Both abused vulnerabilities in Korean financi…
🇰🇷 Korea, Republic of
#FinancialGain
#Espionage
2026-07
On July 28, 2026, malicious beta versions of @joyfill/components and @joyfill/layouts were published to npm with an obfuscated implant embedded in their distribution bundles. Importing an affected package—not merely installing it—triggered a blockchain-re…
🇺🇸 United States
#SupplyChain
#Technology
2026-07
On 22 July 2026, UNC4899 / TraderTraitor compromised AFX's custody bridge after a fake job approach led a developer to clone a malicious repository. The attacker persisted in AFX's JFrog infrastructure, used stolen credentials to abuse an operations basti…
🇬🇧 United Kingdom
#Cryptocurrency
#FinancialGain
2026-07
In June 2026, attackers linked with high confidence to the North Korean state-backed group Sapphire Sleet used a compromised Telegram account of a legitimate industry contact to lure an ORO employee into a fake Microsoft Teams meeting, tricking them into …
#Cryptocurrency
#FinancialGain
2026-06
Mastra was hit by a June 2026 npm supply-chain compromise in which a hijacked or stale maintainer account republished more than 140 Mastra ecosystem packages with a malicious dependency on the typosquatted easy-day-js package. The easy-day-js postinstall …
🇺🇸 United States
#SupplyChain
#Technology
2026-06
A June 8, 2026 compromise of Humanity Protocol's $H token infrastructure began with a Bithumb-themed spear-phishing email that infected a director's Windows laptop and exposed MetaMask data plus production signer keys. The attacker used stolen Ethereum an…
🇭🇰 Hong Kong
#Cryptocurrency
#FinancialGain
2026-04
LeenLee Country Club in Gapyeong disclosed a customer-data breach after police found signs of malware infection on its website server and investigated a possible link to a North Korean Reconnaissance General Bureau hacking group. The company assessed that…
🇰🇷 Korea, Republic of
#DataBreach
#Retail
2026-04
The April 18, 2026 KelpDAO exploit — resulting in approximately $290M in losses — was a sophisticated supply-chain-style RPC poisoning attack attributed to DPRK's TraderTraitor cluster, in which the threat actor compromised two independent RPC nodes used …
🇮🇳 India
#Cryptocurrency
#FinancialGain
2026-04
Endpoint, also called Midnight, is a ransomware campaign reported against South Korean small and medium-sized businesses, with manufacturing victims specifically noted by South Korean authorities. The activity uses malicious email lures, supplier or IT se…
🇰🇷 Korea, Republic of
#FinancialGain
#Manufacturing
2026-04
The Zerion security incident involved a targeted AI-enabled social engineering attack against a team member’s device, which resulted in the compromise of active sessions, credentials, and private keys to internal hot wallets, allowing attackers to steal a…
🇺🇸 United States
#Cryptocurrency
#FinancialGain
2026-04
On April 1, 2026, Drift Protocol lost about $285 million in a coordinated Solana DeFi attack with preliminary indicators consistent with DPRK-linked operations. Attackers used durable nonce transactions and social engineering around multisig signing to ga…
🇦🇺 Australia
#Cryptocurrency
#FinancialGain
2026-03
In March 2026, ESET observed Andariel deploy TigerRAT on a host at a South Korean engineering company and attempt to spread Rook ransomware variants across multiple network endpoints — the first Andariel-attributed activity in ESET telemetry in two years.…
🇰🇷 Korea, Republic of
#FinancialGain
#Manufacturing
2026-03
In March 2026, attackers attributed by security researchers to North Korea-linked UNC1069/Sapphire Sleet compromised Axios npm maintainer access and published malicious axios releases 1.14.1 and 0.30.4. The releases added the malicious dependency plain-cr…
#SupplyChain
#Technology