logo

N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust

ID: da8102be-60b3-5977-8906-45f74ef6aff1

STIX ID: report--da8102be-60b3-5977-8906-45f74ef6aff1

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Socket Security researchers uncovered a North Korea-linked supply-chain campaign dubbed “Contagious Interview” that distributed over 1,700 malicious packages across npm, PyPI, Go, Rust and Packagist to act as loaders for platform-specific second-stage malware. The payloads include infostealers and RAT-like implants (with keystroke logging, browser and wallet data theft, file exfiltration, remote access via AnyDesk, and modular downloads), and the activity is attributed to financially motivated DPRK-linked actor UNC1069 which also uses multi-week social engineering and poisoned legitimate packages (e.g., Axios/WAVESHAPER.V2) to gain initial access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.