logo

New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

ID: d63c2012-cd1f-5192-911e-736b613a382e

STIX ID: report--d63c2012-cd1f-5192-911e-736b613a382e

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: [email protected] (The Hacker News)

...
...

The report describes a series of active, evolving supply-chain attacks targeting the open-source/Web3 developer ecosystem: malicious npm/PyPI packages and GitHub artifacts (campaigns dubbed PromptMink, Contagious Interview/Trader, graphalgo) are used to deliver information stealers and RATs that exfiltrate crypto wallets, credentials, .env/.npmrc files, and source code; activity is attributed to DPRK-aligned actors (Famous Chollima/Shifty Corsair, UNC1069/BlueNoroff) and features AI-generated code, layered dependencies, typosquatting, Rust-based add-ons, and observed C2 infrastructure and IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.