N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust
ID: da8102be-60b3-5977-8906-45f74ef6aff1
STIX ID: report--da8102be-60b3-5977-8906-45f74ef6aff1
Feed Name: The Hacker News
Socket Security researchers uncovered a North Korea-linked supply-chain campaign dubbed “Contagious Interview” that distributed over 1,700 malicious packages across npm, PyPI, Go, Rust and Packagist to act as loaders for platform-specific second-stage malware. The payloads include infostealers and RAT-like implants (with keystroke logging, browser and wallet data theft, file exfiltration, remote access via AnyDesk, and modular downloads), and the activity is attributed to financially motivated DPRK-linked actor UNC1069 which also uses multi-week social engineering and poisoned legitimate packages (e.g., Axios/WAVESHAPER.V2) to gain initial access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
