Related Threat Clusters
-
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
Supply Chain Attack Compromises Popular Rust Crates to Deliver Malware
On August 20, 2026, a supply chain attack targeted the Rust ecosystem, compromising the widely used crates arrayref, append-only-vec, and internment. The attackers injected a malicious dependency, proc-macro1, which…
22 articles · Updated August 20, 2026 -
North Korean Hackers Target macOS Users in Cryptocurrency Theft Campaign
A sophisticated malware campaign targeting macOS users has been linked to North Korean threat group Sapphire Sleet. This operation focuses on cryptocurrency organizations, venture capital firms, and Web3 developers.…
2 articles · Updated June 3, 2026 -
North Korean Sapphire Sleet Targets macOS Users in New Social Engineering Campaign
A North Korean cybercrime group known as Sapphire Sleet has launched a social engineering campaign targeting macOS users, as reported by Microsoft's Threat Intelligence unit. The campaign involves tricking users into…
7 articles · Updated April 17, 2026 -
Sapphire Sleet Malware Campaign Targets macOS Users via Fake Zoom SDK Update
A new cyber campaign targeting macOS users has been launched by the North Korean threat actor Sapphire Sleet. The attackers are distributing malware through a fake Zoom SDK update, tricking users into executing…
2 articles · Updated April 17, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
New Threat Actor JINX-0164 Targets Cryptocurrency Organizations
A new threat actor, JINX-0164, has been identified targeting cryptocurrency firms using custom macOS malware and social engineering tactics. Active since mid-2025, the group employs fake recruiter approaches to gain…
14 articles · Updated May 28, 2026 -
Exploitation Attempts on TP-Link Routers via CVE-2023-33538 Linked to Mirai Malware
Hackers are actively targeting a command injection vulnerability, CVE-2023-33538, affecting several end-of-life TP-Link router models, including TL-WR940N and TL-WR841N. This vulnerability allows attackers to execute…
11 articles · Updated April 17, 2026 -
North Korean Hackers Use AI Deepfakes in Crypto Attacks
Google's Mandiant security team reported that North Korean hackers, identified as UNC1069 or 'CryptoCore', are employing AI-generated deepfakes in fraudulent video meetings to target cryptocurrency companies. The…
20 articles · Updated February 10, 2026
Recent Intelligence Reports
- Rust Supply Chain Attack On Arrayref Significant Overlap With Dprk Campaigns — www.wiz.io · August 21, 2026
- North Korean Hackers Tied to Rust Supply Chain Attack — Infosecurity-Magazine · August 21, 2026
- Backdoored Rust packages hit crates.io, exposing developers to malware at build time — Csoonline · August 21, 2026
- Did North Korean hackers launch the supply chain attack on arrayref? — www.cryptopolitan.com · August 21, 2026
- Amazon links Debug, Chalk NPM supply — Bleepingcomputer · July 30, 2026
- Amazon links four poisoned npm packages to one North Korean crew — Theregister · July 30, 2026
- Amazon pins multiple open source compromises on North Korea — Computerweekly · July 30, 2026
- North Korean hackers expand open-source software supply chain attacks: Amazon — Nknews · July 30, 2026