Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
ID: ef7654f5-f343-5df6-a06c-77ae88c4ea31
STIX ID: report--ef7654f5-f343-5df6-a06c-77ae88c4ea31
Feed Name: securityonline.info
TrendMicro researchers describe Void Dokkaebi (Famous Chollima), a North Korea-linked intrusion set that has evolved into a self-propagating developer-focused supply-chain campaign: attackers embed malicious Visual Studio Code task configurations and injected code to steal cryptocurrency credentials, signing keys, and CI/CD access, spreading across public and corporate repositories (750+ infected repos, 500+ malicious VS Code tasks, evidence of commit tampering) and using blockchain platforms for resilient payload staging.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
