Kryptovalutaticker:
sysadmin från Cyber Security News

North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks

Tushar Subhra Dutta
5 hours ago
2 Visningar
0 Kommentarer
North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks

North Korean-linked hackers are turning trusted npm packages into an entry point for widespread software supply-chain attacks. By compromising the accounts of legitimate package maintainers, the attackers can slip malicious updates into tools that developers and businesses already trust. The campaigns affected the typo-crypto, debug, chalk, and axios packages at different points between March 2025 and March 2026. Organizations that automatically installed the newest versions could unknowingly pull in the malicious code during routine development or build activity. Analysts at AWS identified the campaigns as the work of a DPRK-linked actor tracked as SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!