npm

Microsoft cuts API key lifetimes after North Korean npm attack

A North Korea-linked hacking group compromised more than 130 packages within the Mastra AI framework on npm, the JavaScript package registry owned by Microsoft through GitHub, in what multiple security firms have called one of the largest open-source supply chain…

North Korea denies role in npm attacks after 11-nation alert

A pair of newly disclosed campaigns illustrate how North Korean hacking groups are escalating their attacks on the open-source software ecosystem, compromising widely used JavaScript packages and leveraging blockchain technology to conceal malware infrastructure.