eSentire reports that two malicious Axios npm versions, 1.14.1 and 0.30.4, were published through a compromised maintainer account and remained live for about three hours. The tampered packages added a malicious dependency that ran a postinstall payload, …
« Reports in 2026
554 reports
A suspected Kimsuky phishing operation used a Korean Army K-ICTC themed lure to target military, defense, diplomacy, and related research audiences. The victim-facing archive contained a convincing invitation PDF and a PDF-disguised LNK shortcut that down…
A cluster of malicious npm packages published between April 6 and April 9, 2026 delivered OtterCookie variants, described as a credential-theft and backdoor toolchain attributed to North Korean threat actors. The campaign used a two-layer supply-chain pat…
Socket identifies a new cluster in North Korea’s Contagious Interview operation that published malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist. The packages impersonated developer tools while hiding loaders inside ordinary-lookin…
An investigation into the Mentonex GitHub organization found an active npm backdoor chain, fake developer personas, and facilitator-recruitment activity that the author says maps closely to documented DPRK tradecraft. The malicious chain used logkitx, log…
Jason Reaves links NodeJS stealer and backdoor infrastructure to activity resembling DPRK developer-targeting campaigns that use fake interviews or attacker-supplied code repositories. The excerpt shows an npm package, npm-doc-builder, executing a postins…
Zscaler ThreatLabZ frames North Korean cyber attribution as increasingly difficult because Lazarus and Kimsuky have evolved into umbrella structures with specialized sub-clusters, shared tooling, and overlapping infrastructure. The material traces Lazarus…
A compromise of the Axios npm package introduced malicious versions 1.14.1 and 0.30.4 that added a covert dependency and executed a postinstall payload when developers or CI/CD systems installed the package. The excerpt attributes the activity to UNC1069,…
Breakglass Intelligence found an exposed phishing backend at arnptec[.]com after investigating a Vercel-hosted Naver credential-harvesting page, curly-spoon-sigma[.]vercel[.]app. Directory listing revealed ten operator directories, nine campaign themes, r…
Drift describes an April 2026 compromise that followed months of relationship-building by personas posing as a quantitative trading firm seeking protocol integration. The attackers allegedly engaged Drift contributors at conferences, created a Telegram gr…
Resecurity describes a malicious npm supply-chain campaign in which plain-crypto-js was embedded as a dependency in compromised Axios versions and executed through npm's postinstall lifecycle hook. The Node.js dropper used layered obfuscation, including s…
A malicious npm account, gemini-check, published gemini-ai-checker as a fake Google Gemini token verifier and used related packages express-flowlimit and chai-extensions-extras that shared the same Vercel staging infrastructure. The package assembled a re…
An attacker drained approximately $285 million from Drift Protocol after obtaining pre-signed Solana durable-nonce transactions from Security Council members and using them to seize administrative authority. The attacker created a falsely valued token, as…
Kimsuky is assessed to have distributed malicious `.pdf.lnk` files disguised as a resume and North Korea policy documents, using a multi-stage PowerShell chain to collect host information and exfiltrate it. The infection saves and runs `firefox.ps1`, esta…
Panther analyzed jsonspack as a DPRK-labeled npm supply-chain campaign involving 27 malicious packages published by eight accounts between March 18 and March 31, 2026, with 3,739 recorded downloads. The packages used developer-tooling names such as Chai p…