The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
ID: b075cf8e-5522-55bd-8b76-dc261a199888
STIX ID: report--b075cf8e-5522-55bd-8b76-dc261a199888
Feed Name: securityonline.info
Threat Score
Panther Threat Research uncovered a 30-day, large-scale npm supply-chain malware campaign linked to North Korean actors that used 108 malicious packages (261 versions) to infiltrate developer and CI/CD systems, exfiltrate crypto keys, cloud/DevOps secrets, and AI workflow data, and establish persistent access via techniques including blockchain-based dead-drops and trojanized libraries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
