Kryptovaluta-ticker:
sysadmin fra Cyber Security News

North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks

Tushar Subhra Dutta
5 hours ago
2 Visninger
0 Kommentarer
North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks

North Korean-linked hackers are turning trusted npm packages into an entry point for widespread software supply-chain attacks. By compromising the accounts of legitimate package maintainers, the attackers can slip malicious updates into tools that developers and businesses already trust. The campaigns affected the typo-crypto, debug, chalk, and axios packages at different points between March 2025 and March 2026. Organizations that automatically installed the newest versions could unknowingly pull in the malicious code during routine development or build activity. Analysts at AWS identified the campaigns as the work of a DPRK-linked actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring...

Les hele artikkelen hos kilden.

Delta i diskusjonen — kommenter, stem og del lenker.

Registrer
Var dette nyttig?
Del:

Kommentarer (0)

Vennligst logg inn eller registrer deg for å delta i diskusjonen

Ingen kommentarer ennå. Bli den første til å kommentere!