daily cyber × ai intelligence

index

tagged

[dprk]

10 editions · 12 items

August 28, 2026

  • A compromised npm release uses Ethereum as a dead drop. Nextron's artifact scanner caught @testrelic/playwright-analytics 2.13.0, whose obfuscated postinstall resolves a C2 (23.27.20.187:443) via an on-chain lookup, then fetches /boot/init and evals the JS. Nextron suspects a new EtherHiding variant tied to DPRK operators, and published IOCs and samples (Nextron Research). · Supply Chain & Takedowns

in Australia Charges Two Over the TeamPCP Supply-Chain Spree

August 2, 2026

  • DPRK actor "PolinRider" behind dozens of npm, Go, and PHP compromises. New analysis extends the North Korean campaign already linked to the axios/debug/chalk incidents (earlier coverage), detailing how developer machines are hijacked via social engineering to silently push malicious releases; recommended mitigations include token rotation, dependency scanning, and access hardening (opensourcemalware.com). · Supply Chain
  • DPRK macOS malvertising revives Contagious Interview. A new iteration redirects victims to full-screen fake update sequences to deliver crypto-stealing malware on macOS (The Hacker News). · Threat Intelligence

in Coldcard Wallet Theft Climbs Past $88M as Attackers Drain Weak-Entropy Addresses in Waves

July 31, 2026

  • Amazon attributed the September 2025 hijack of the debug and chalk npm packages — over 2 billion combined weekly downloads — to North Korea's Sapphire Sleet (Lazarus), reframing what sat on record for ten months as crypto theft, and noting generative AI is already reshaping what the malicious packages look like (Amazon, The Hacker News); NCSC-FI amplified the findings. This sharpens the DPRK attribution flagged in earlier coverage. · Threat Activity

in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests

July 23, 2026

  • Kimsuky compromises South Korean groupware vendors with a new Gomir variant. ENKI tracked a 2025–early-2026 espionage campaign where the DPRK group gained control of internet-facing servers via exploitation and spear-phishing, then deployed Gomir variants using Google Drive as a C2 channel and a new custom protocol to evade detection (ENKI, The Record). · Threat Activity

in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident

July 22, 2026

  • The DPRK npm supply-chain campaign added more packages, with Nextron flagging vectormark v1.0.0 and rollup-packages-polyfill-core v0.13.9 (which silently installs vectormark). The three-stage, RC4-encrypted payload pulls obfuscated JS from api[.]avax-test[.]dev and steals SSH keys, AWS credentials, Docker tokens, .env files, and git history (earlier coverage). Nextron. · Threat Activity
  • DPRK's "ClickFake Interview" campaign is impersonating recruiting platforms to drop the PylangGhost and GolangGhost RATs via spoofed platform and panel API endpoints. SOCRadar. · Threat Activity

in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face