Open Source Malware reports that the DPRK-linked PolinRider supply-chain campaign expanded from 675 to 1,951 confirmed compromised GitHub repositories across 1,047 owners in five weeks. The campaign injects obfuscated JavaScript into developer configurati…
« Reports in 2026
593 reports
APT37 used Facebook accounts presenting locations in Pyongyang and Pyongsong to identify targets, build trust through friend requests and Messenger conversations, and move victims toward Telegram delivery. The lure claimed encrypted military-weapons PDF d…
APT37 used Facebook accounts presenting locations in Pyongyang and Pyongsong to identify targets, build trust through friend requests and Messenger conversations, and move victims toward Telegram delivery. The lure claimed encrypted military-weapons PDF d…
Four public GitHub repositories contained the same obfuscated stage-0 JavaScript loader appended after otherwise legitimate framework or build-tool configuration exports. The loader family is aligned with publicly reported XCTDH and DEV#POPPER activity, w…
Breakglass analyzed a live Kimsuky C2 tied to a CHM-based intrusion chain after a MalwareBazaar submission exposed check.nid-log[.]com serving multiple payload stages. The chain uses hh.exe, PowerShell, certutil, and wscript to decode and execute VBScript…
OpenSourceMalware attributes PolinRider to a DPRK-linked actor connected to Lazarus activity, Contagious Interview, and TasksJacker, with confirmed infections across 1,951 public GitHub repositories and 1,047 owners as of April 11, 2026. The campaign appe…
North Korea-linked UNC1069 expanded Contagious Interview supply-chain activity across npm, PyPI, Go, Rust, and PHP, with Socket tracking more than 1,700 malicious packages tied to the operation. The same broader activity included a separate Axios maintain…
Panther analyzed [email protected], an npm package attributed in the excerpt to DPRK/Famous Chollima activity and built to target developers running automated Polymarket trading bots. The package masqueraded as a logging utility and executed at require()…
OpenAI identified exposure to the broader Axios supply-chain compromise when a GitHub Actions workflow used for macOS app signing downloaded and executed malicious Axios version 1.14.1 on March 31, 2026. The affected workflow had access to certificate and…
Malicious Axios npm versions `[email protected]` and `[email protected]` were observed in a customer environment after attackers abused npm lifecycle execution through a hidden dependency. The postinstall chain launched shell and PowerShell activity, downloaded a s…
KrCERT/CC warned that Inswave WGear, an enterprise banking electronic-finance component used for large Excel processing, contains a remote code execution vulnerability. The affected scope is WGear 1.100.7.0205 and earlier, except 1.100.2.25091, with remed…
Drift Protocol was drained after an attacker spent weeks preparing a fake Solana token, durable nonce transactions, and social-engineering conditions around multisig signing. The attacker created CarbonVote Token, seeded minimal liquidity, wash-traded it …
ReversingLabs found the graphalgo fake recruiter-test campaign continuing with new fake blockchain companies and GitHub organizations designed to make malicious job assignments appear legitimate. The activity used recruiter personas, fake company infrastr…
Chainalysis reports that Drift Protocol lost about $285 million on April 1, 2026 in a highly coordinated Solana DeFi attack with preliminary indicators consistent with DPRK-linked operations, though formal attribution was still pending. According to Drift…
The archived thread links the axios supply-chain attack to BlueNoroff's GhostCall campaign and says an updated SysPhon, also known as WAVESHAPER, was used to profile valuable hosts and fetch additional payloads. The attack abused an attacker-controlled de…