Crypto Ticker:
sysadmin from Cyber Security News

North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks

Tushar Subhra Dutta
5 hours ago
4 Views
0 Comments
North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks

North Korean-linked hackers are turning trusted npm packages into an entry point for widespread software supply-chain attacks. By compromising the accounts of legitimate package maintainers, the attackers can slip malicious updates into tools that developers and businesses already trust. The campaigns affected the typo-crypto, debug, chalk, and axios packages at different points between March 2025 and March 2026. Organizations that automatically installed the newest versions could unknowingly pull in the malicious code during routine development or build activity. Analysts at AWS identified the campaigns as the work of a DPRK-linked actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!