|
News North Korean hackers expand supply chain attack campaign across ecosystemsCampaign targeting developers could allow attackers to steal credentials and set up further attacks, researchers warn North Korean-linked cybercriminals have expanded a long-running campaign targeting software supply chains across multiple open-source software ecosystems, exposing software developers and organizations that rely on open-source software packages to a broader range of attacks. In a report published Wednesday, U.S. security firm Socket said it identified 162 malicious release artifacts across 108 packages and browser extensions tied to the “PolinRider” campaign, which it linked to North Korea’s broader Contagious Interview operation targeting developers. While some of the attack techniques have appeared in previous North Korean campaigns, researchers said the operation has significantly broadened its reach © Korea Risk Group. All rights reserved. |





