A small JavaScript stealer with fingerprints of North Korean developer-targeting campaigns has been found riding a cluster of malicious packages.
Rapid7 finds a North Korea-linked toolkit hiding inside trojanized HAProxy builds at two South Korean firms.
The Rust project yanked three poisoned crates after a compromised account shipped a build-time backdoor.
Check Point ties a Windows zero-day to Lazarus attacks on defense firms using fake job offers.
Sting startup hired three suspected Pyongyang IT workers.
Kimsuky runs local AI models to sharpen phishing lures.
Amazon attributes the debug and chalk npm hijacks to the North Korean group behind the axios attack.
North Korean threat actors embed malware payload fragments inside SVG country flag images distributed through fake developer job interviews and…