Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

esecurityplanet+1esecurityplanet+1A pair of newly disclosed campaigns illustrate how North Korean hacking groups are escalating their attacks on the open-source software ecosystem, compromising widely used JavaScript packages and leveraging blockchain technology to conceal malware infrastructure.
Amazon Amazon.com, Inc. Threat Intelligence published a report on July 28 linking four npm supply-chain compromises — involving the packages Axios, debug, chalk, and typo-crypto — to Sapphire Sleet, a threat actor associated with North Korea. The campaign spanned from March 2025 to March 2026, with Amazon assessing the attribution at medium confidence based on shared command-and-control indicators, code reuse, and post-install hooks.esecurityplanet+2
Rather than exploiting technical vulnerabilities in npm infrastructure, the attackers targeted the developers authorized to maintain popular packages, using social engineering to steal credentials and push malicious updates through legitimate accounts. Axios alone receives more than 100 million weekly downloads, illustrating the potential scale of exposure.linkedin+2
Separately, researchers at OpenSource Malware identified a technique they dubbed "NullReceiver," found in two malicious npm packages — bianira-ui and fluid-type-ui — that impersonated Tailwind CSS plugins. The technique encodes a command-and-control server's IP address inside the recipient field of an empty Ethereum transaction, making the activity appear indistinguishable from normal wallet transfers.cybersecuritynews+2
The zero-value transactions contain no smart contract calls or payload data, allowing malware to retrieve instructions from a public blockchain that defenders cannot easily take down. OpenSource Malware connected the campaign to the DPRK-linked Contagious Interview operation, which has repeatedly targeted developers through convincing software lures.cybersecuritynews
The findings arrive days after the United States, South Korea, Japan, and eight other countries issued a joint alert on August 1 warning that North Korean IT workers use false identities and AI tools to secure remote employment and funnel income toward Pyongyang's weapons programs. The FBI said eight individuals have been sentenced to prison in 2026 for their roles in such schemes.upi+2
North Korea responded on Tuesday through state news agency KCNA, calling the warnings "politically motivated" and accusing the United States of "militarizing cyberspace". A foreign ministry spokesperson dismissed the joint alert as an attempt to "tarnish its image and justify pressure on sovereign states".reuters