September 3, 2026
- BindsNET compromised in DPRK-linked NullReceiver activity. Nextron Research says the 1.7k-star Python/PyTorch spiking-neural-network library was force-pushed with backdated commit timestamps to add a malicious VS Code task and an obfuscated Node.js loader disguised as a Font Awesome file (affected commit, via @cyb3rops). The VS Code task vector means simply opening the repo is enough.
· Supply Chain
in Ten Hours, Fifty Techniques: AI Agents Ran the Whole Ransomware Intrusion
August 29, 2026
- North Korean remote workers are moving beyond IT into sales, marketing and medical roles. Huntress identified five suspected cases in 2026 by pivoting on shared VPN, proxy and hosting infrastructure; operatives used stolen or altered IDs to get hired and remotely controlled company-issued laptops (Huntress, Dark Reading).
· Threat Activity
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 28, 2026
- A compromised npm release uses Ethereum as a dead drop. Nextron's artifact scanner caught
@testrelic/playwright-analytics 2.13.0, whose obfuscated postinstall resolves a C2 (23.27.20.187:443) via an on-chain lookup, then fetches /boot → /init and evals the JS. Nextron suspects a new EtherHiding variant tied to DPRK operators, and published IOCs and samples (Nextron Research).
· Supply Chain & Takedowns
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 17, 2026
- North Korea has burned the same Windows driver four times in four years. Researchers note DPRK operators keep returning to
afd.sys, the Ancillary Function Driver for WinSock, as a reliable exploitation target (@cyb3rops).
· Threat Intelligence
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 2, 2026
- DPRK actor "PolinRider" behind dozens of npm, Go, and PHP compromises. New analysis extends the North Korean campaign already linked to the axios/debug/chalk incidents (earlier coverage), detailing how developer machines are hijacked via social engineering to silently push malicious releases; recommended mitigations include token rotation, dependency scanning, and access hardening (opensourcemalware.com).
· Supply Chain
- DPRK macOS malvertising revives Contagious Interview. A new iteration redirects victims to full-screen fake update sequences to deliver crypto-stealing malware on macOS (The Hacker News).
· Threat Intelligence
in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves
July 31, 2026
- Amazon attributed the September 2025 hijack of the debug and chalk npm packages — over 2 billion combined weekly downloads — to North Korea's Sapphire Sleet (Lazarus), reframing what sat on record for ten months as crypto theft, and noting generative AI is already reshaping what the malicious packages look like (Amazon, The Hacker News); NCSC-FI amplified the findings. This sharpens the DPRK attribution flagged in earlier coverage.
· Threat Activity
in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests
July 26, 2026
- A group of former DPRK military cyber operators reportedly hacked their own state banks — Chosun Central Bank and Foreign Trade Bank — skimming small amounts below detection thresholds and laundering via crypto and Chinese brokers before arrests on July 12, per Daily NK.
· Threat Activity
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 23, 2026
- Kimsuky compromises South Korean groupware vendors with a new Gomir variant. ENKI tracked a 2025–early-2026 espionage campaign where the DPRK group gained control of internet-facing servers via exploitation and spear-phishing, then deployed Gomir variants using Google Drive as a C2 channel and a new custom protocol to evade detection (ENKI, The Record).
· Threat Activity
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 22, 2026
- The DPRK npm supply-chain campaign added more packages, with Nextron flagging
vectormark v1.0.0 and rollup-packages-polyfill-core v0.13.9 (which silently installs vectormark). The three-stage, RC4-encrypted payload pulls obfuscated JS from api[.]avax-test[.]dev and steals SSH keys, AWS credentials, Docker tokens, .env files, and git history (earlier coverage). Nextron.
· Threat Activity - DPRK's "ClickFake Interview" campaign is impersonating recruiting platforms to drop the PylangGhost and GolangGhost RATs via spoofed platform and panel API endpoints. SOCRadar.
· Threat Activity
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
June 18, 2026
- DPRK-linked PolinRider continues evolving —
tailwind-color-shades typosquat uses a blockchain dead-drop loader chain (TRON→Aptos→BSC→XOR→eval) to deliver Beavertail → InvisibleFerret, with a new XOR key and obfuscator build (Nextron).
· Supply Chain
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel