Last week’s reporting covered DPRK activity against developers, software supply chains, and remote hiring. Genians found Kimsuky infrastructure running local AI tools and document retrieval software. CrowdStrike attributed the poisoning of 131 AI framework packages to STARDUST CHOLLIMA, while an investigation into North Korean command-and-control servers found evidence of intrusions at hundreds of organizations.
Last week’s DPRK-related reporting focused on open-source compromise, blockchain-based command delivery, and attacks through trusted South Korean websites and security software. Supply-chain campaigns first compromised developers or maintainers, then pushed malicious code into legitimate npm packages and Go modules. Separate research documented APT37’s NarwhalRAT infrastructure and an AFX bridge theft attributed in a detailed post-mortem to UNC4899 / TraderTraitor.
Fake meetings and job interviews drove several DPRK-linked operations last week. BlueNoroff, Sapphire Sleet, and Famous Chollima used compromised contacts or recruiter personas to direct targets to imitation meeting pages, then persuaded Windows and macOS users to execute commands. The resulting malware targeted browser credentials, cryptocurrency wallets, and remote control of the host.
Last week’s reporting joined two risks that often begin with developer access. Fake coding tests delivered cross-platform credential theft, while stolen developer accounts and package publishing access spread malicious code through GitHub and npm. PolinRider’s confirmed footprint rose to 4,367 repositories, and separate research connected the ChainVeil and ViteVenom package clusters to the same campaign with differing attribution confidence.
Last week’s reporting covered developer ecosystem compromise, digital-asset theft and laundering, and an APT37 RokRAT campaign. PolinRider expanded from npm into Go modules, Packagist packages, and Chrome extensions. The reporting tied that expansion to compromised GitHub accounts and repository release paths, putting source-control identity at the center of package security.
Last week’s reporting expanded the visible scale of DPRK access operations around developers. Ossprey mapped hundreds of Contagious Interview payload URLs and a separate Node.js RAT cluster. Other researchers documented malicious open-source packages, trojanized interview projects, compromised maintainer accounts, and GitHub personas apparently built to support fraudulent employment.
Last week’s reporting covered several routes into developer and financial environments. Internal records obtained by the BBC described a managed DPRK IT worker operation built around borrowed identities, assigned roles, close supervision, and foreign-currency quotas. Malware research documented memory-resident Windows tooling, macOS surveillance implants, malicious npm packages, and Kimsuky phishing chains.
Last week’s reporting centered on developer access as a route into software supply chains and cryptocurrency systems. The Mastra incident put that risk into production at scale: a compromised maintainer account added easy-day-js to more than 140 npm packages, exposing developer workstations and CI runners to a cross-platform Node.js implant. Other reports described malicious code hidden in configuration files, blockchain-based payload resolution, fake interviews, and poisoned packages.
The Humanity Protocol $H compromise was the clearest incident last week. A phishing attachment led to remote access on a director’s Windows endpoint, theft of wallet and signer material, changes to bridge and contract authority, unauthorized minting, and token sales. The incident joined endpoint security directly to protocol governance and market impact.
Last week’s reporting concentrated on developer supply chains and the financial operations around cryptocurrency theft. Lazarus-linked npm brandjacking and Contagious Interview activity targeted routine dependency installation and developer workstations, while new analysis of Copperhedge described the path from server exploitation to in-memory control.