« 2024 »

654 reports

2024-04-25 • Securonix

Securonix tracks DEV#POPPER as an ongoing social engineering campaign likely tied to North Korean threat actors and aimed at software developers. Attackers pose as interviewers, send GitHub-hosted coding tasks, and rely on the target running a malicious N…

#NPM #DevPopper #T1082 #T1059.003 #T1070.004 #T1041 #T1560 #T1059.006 #T1059.001 #T1027.010 #T1033 #T1132
2024-04-24 • Phylum

Phylum linked new npm publications on 23 April 2024 to a previously reported North Korea-attributed campaign against open-source package ecosystems. The packages react-dom-production-script and hardhat-daemon used a preinstall hook to run deference.js as …

#macOS #NPM
2024-04-20 • Thecyberwire

Greg Lesnewich, senior threat researcher at Proofpoint, sits down to discuss "From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering." Since 2023, TA427 has directly solicited foreign policy experts for their opinions on nuclear disa…

#Podcast #TA427 #DMARC