North Korea's Moonstone Sleet Widens Distribution of Malicious Code
ID: d6eeb923-c96f-5e11-97fe-61e0875a9de3
STIX ID: report--d6eeb923-c96f-5e11-97fe-61e0875a9de3
Feed Name: Dark Reading
Date Published: 2024-06-13
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers observed a North Korean APT, Moonstone Sleet, widening its distribution of malicious npm packages in public registries to poison the open-source software supply chain; the actor uses single-package installers that execute payloads on install, has added obfuscation and Linux targeting, and is distinct from Lazarus in its packaging and delivery methods, posing increased risk to developers and consuming organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
