« 2025 »

778 reports

2025-11-29 • Wickeren

The researcher attributes DredSoftLabs to WageMole, a DPRK state-sponsored remote-employment operation that uses fake identities, social engineering, job platforms, and stolen personal data to pursue Western remote work. A GitHub search pivot on an encode…

#Wagemole
2025-11-26 • Socket

Socket tracks North Korea’s Contagious Interview operation expanding its npm supply-chain activity with at least 197 additional malicious packages and more than 31,000 downloads, targeting blockchain and Web3 developers through fake interviews and test as…

#NPM #ContagiousInterview #OtterCookie #T1082 #T1119 #T1005 #T1587.001 #T1041 #T1113 #T1608.001 #T1195.002 #T1115 #T1083 #T1497 #T1056.001 #T1059.007 #T1036 #T1204.002 #T1555.003 #T1583.006 #T1547.001 #T1539 #T1583.001 #T1656 #T1105 #T1204.005 #T1571 #T1657 #T1587 #T1585 #T1555.001 #T1546.016 #T1217