Zscaler ThreatLabZ frames North Korean cyber attribution as increasingly difficult because Lazarus and Kimsuky have evolved into umbrella structures with specialized sub-clusters, shared tooling, and overlapping infrastructure. The material traces Lazarus…
« Reports in 2026
593 reports
A compromise of the Axios npm package introduced malicious versions 1.14.1 and 0.30.4 that added a covert dependency and executed a postinstall payload when developers or CI/CD systems installed the package. The excerpt attributes the activity to UNC1069,…
Breakglass Intelligence found an exposed phishing backend at arnptec[.]com after investigating a Vercel-hosted Naver credential-harvesting page, curly-spoon-sigma[.]vercel[.]app. Directory listing revealed ten operator directories, nine campaign themes, r…
Drift describes an April 2026 compromise that followed months of relationship-building by personas posing as a quantitative trading firm seeking protocol integration. The attackers allegedly engaged Drift contributors at conferences, created a Telegram gr…
Resecurity describes a malicious npm supply-chain campaign in which plain-crypto-js was embedded as a dependency in compromised Axios versions and executed through npm's postinstall lifecycle hook. The Node.js dropper used layered obfuscation, including s…
A malicious npm account, gemini-check, published gemini-ai-checker as a fake Google Gemini token verifier and used related packages express-flowlimit and chai-extensions-extras that shared the same Vercel staging infrastructure. The package assembled a re…
An attacker drained approximately $285 million from Drift Protocol after obtaining pre-signed Solana durable-nonce transactions from Security Council members and using them to seize administrative authority. The attacker created a falsely valued token, as…
Kimsuky is assessed to have distributed malicious `.pdf.lnk` files disguised as a resume and North Korea policy documents, using a multi-stage PowerShell chain to collect host information and exfiltrate it. The infection saves and runs `firefox.ps1`, esta…
Panther analyzed jsonspack as a DPRK-labeled npm supply-chain campaign involving 27 malicious packages published by eight accounts between March 18 and March 31, 2026, with 3,739 recorded downloads. The packages used developer-tooling names such as Chai p…
DCSO analyzed public indicators from the axios npm compromise and found infrastructure overlaps suggesting possible connections to the DPRK-linked BlueNoroff cluster. The attacker used newly created Proton Mail accounts, compromised the axios maintainer a…
Cisco Talos found that attackers published malicious Axios npm versions 1.14.1 and 0.30.4 on March 31, 2026, leaving the widely used JavaScript HTTP client exposed for about three hours. The modified packages introduced a fake dependency, plain-crypto-js,…
High-impact Node.js and npm maintainers reported being targeted by the same social engineering campaign that led to the Axios npm compromise, indicating a coordinated effort against trusted open-source maintainers rather than a one-off incident. The playb…
North Korea’s malware ecosystem is presented as a deliberately compartmentalized portfolio built for mission specialization, resilience, and attribution ambiguity. The espionage track, associated in the text with Kimsuky, emphasizes low-noise access, cred…
NVISO describes hunting and response activity for the Axios npm supply-chain incident, where compromised Axios releases added the trojanized [email protected] dependency and deployed cross-platform RAT payloads. Its MDR telemetry observed activity mai…
TRM Labs assessed that the April 2026 Drift Protocol theft was likely carried out by North Korean hackers, after attackers drained about $285 million from the Solana-based perpetual futures exchange. On-chain staging began weeks earlier with Tornado Cash …