Top Node.js Maintainers Targeted in Sophisticated Social Engineering Scheme
ID: 0fc496bd-6c32-515a-9da1-3c0f9c921c15
STIX ID: report--0fc496bd-6c32-515a-9da1-3c0f9c921c15
Feed Name: cybersecurityNews.com
Threat Score
**Active supply-chain-focused social-engineering campaign:** A patient, sophisticated operation (linked to UNC1069) is targeting prominent Node.js and npm maintainers via LinkedIn and Slack, using fake personas and cloned meeting sites to trick victims into downloading a RAT that steals browser cookies, cloud credentials, and developer tokens — allowing attackers to bypass 2FA and publish malicious code to the npm registry, potentially affecting millions of downstream users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
