Related Threat Clusters
-
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
Supply Chain Attack Compromises Popular Rust Crates to Deliver Malware
On August 20, 2026, a supply chain attack targeted the Rust ecosystem, compromising the widely used crates arrayref, append-only-vec, and internment. The attackers injected a malicious dependency, proc-macro1, which…
22 articles · Updated August 20, 2026 -
North Korean Hackers Target macOS Users in Cryptocurrency Theft Campaign
A sophisticated malware campaign targeting macOS users has been linked to North Korean threat group Sapphire Sleet. This operation focuses on cryptocurrency organizations, venture capital firms, and Web3 developers.…
2 articles · Updated June 3, 2026 -
North Korean Group UNC1069 Behind Axios npm Supply Chain Attack
On March 31, 2026, a supply chain attack targeting the Axios npm package was attributed to the North Korean cyber group UNC1069. This attack exploited vulnerabilities in the software supply chain, affecting numerous…
5 articles · Updated April 1, 2026 -
North Korea's UNC1069 Targets Cryptocurrency Professionals with Fake Meetings
A North Korea-linked threat actor, UNC1069, is executing a targeted campaign aimed at cryptocurrency and Web3 professionals. The attackers lure victims into fake Zoom, Google Meet, and Microsoft Teams meetings, where…
2 articles · Updated April 20, 2026 -
North Korean Hackers Exploit Fake Microsoft Teams Domains for Malware Attacks
Threat actors linked to North Korea, identified as UNC1069, are using fake Microsoft Teams domains to execute social engineering attacks and distribute malware. These attacks target corporate users by mimicking the…
4 articles · Updated April 6, 2026 -
Mercor Cyberattack Linked to LiteLLM Supply Chain Compromise
AI recruiting startup Mercor confirmed it was impacted by a supply chain attack linked to the LiteLLM project, which has affected thousands of organizations. The breach was attributed to the hacking group TeamPCP, with…
30 articles · Updated April 1, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
New Threat Actor JINX-0164 Targets Cryptocurrency Organizations
A new threat actor, JINX-0164, has been identified targeting cryptocurrency firms using custom macOS malware and social engineering tactics. Active since mid-2025, the group employs fake recruiter approaches to gain…
14 articles · Updated May 28, 2026 -
North Korean Hackers Steal $100K from Zerion Using AI Social Engineering
Zerion, a DeFi crypto wallet provider, reported a theft of approximately $100,000 from its hot wallets due to an AI-enhanced social engineering attack linked to North Korean hackers. The attack, which targeted employee…
5 articles · Updated April 15, 2026
Recent Intelligence Reports
- Did North Korean hackers launch the supply chain attack on arrayref? — www.cryptopolitan.com · August 21, 2026
- Sapphire Sleet — cloud.google.com · August 4, 2026
- A little-known npm package was North Korea’s warm — Cyberscoop · July 29, 2026
- Threat Actors Target Crypto Orgs — www.wiz.io · June 6, 2026
- North Korean APT Targets macOS to Steal Crypto Wallets and SSH Keys — Gbhackers · June 3, 2026
- North Korean hackers target macOS users with advanced malware campaign — Cybernews · June 1, 2026
- New Threat Actor Jinx — Infosecurity-Magazine · May 28, 2026
- North Korea — Cybersecuritynews · April 20, 2026