[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fijehKXpprCO2JByEL8bt5Ir1oB0KYVMiCpq4dHdFK1Y":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"e2f63bab-6a79-49eb-a685-6d64b1c46c8c","north-korean-hackers-poison-open-source-ecosystem-with-108-malicious-packages","8e206d1b-2d11-4ee3-848f-07e05380ab88","North Korean Hackers Poison Open-Source Ecosystem with 108 Malicious Packages","North Korean threat actors exploited developer trust in open-source ecosystems by publishing 108 malicious packages across npm, Packagist, Go, and Chrome extensions, targeting developers and cryptocurrency professionals through fake job recruitment lures. The attackers also compromised GitHub maintainer accounts and rewrote Git history to hide malicious code, making detection significantly harder. This campaign demonstrates how supply chain attacks can weaponize the tools developers rely on daily, turning the software development pipeline into an attack vector. The combination of social engineering and legitimate-looking package repositories amplifies the reach and credibility of the attack, putting entire downstream user bases at risk.","**Immediate actions:**\n- Audit all recently installed npm, Packagist, and Go packages against known malicious package lists published by threat intelligence feeds.\n- Remove or quarantine any suspicious browser extensions, especially those installed during unsolicited job recruitment interactions.\n- Reset credentials for any GitHub maintainer accounts that may have been exposed to phishing or social engineering.\n\n**Long-term improvements:**\n- Implement a software composition analysis (SCA) tool in your CI\u002FCD pipeline to automatically flag unverified or newly published packages before they enter production.\n- Enforce multi-factor authentication (MFA) on all source code repository accounts, including GitHub, npm, and similar platforms.\n- Establish a vetted internal package registry that mirrors only approved open-source dependencies, preventing direct pulls from public repositories.\n\n**Detection measures:**\n- Monitor Git repository history for unexpected rewrites, force-pushes, or commit signature anomalies that could indicate tampering.\n- Deploy endpoint detection tools capable of identifying post-install scripts and unusual process executions triggered by package installation.\n- Train developers to recognize job-recruitment-based social engineering tactics, particularly unsolicited technical coding challenges or offer-linked repositories.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-161: Supply Chain Risk Management","NIST SP 800-218: Secure Software Development Framework (SSDF)","NIST AC-2: Account Management","NIST SI-7: Software, Firmware, and Information Integrity","NIST SA-12: Supply Chain Protection","SLSA Supply Chain Levels for Software Artifacts (Level 2+)","ITIL Change Management: Controlled software change and version control","GDPR Article 32: Security of Processing (for organizations handling EU personal data via affected software)","published","2026-07-04T12:20:21.856392+00:00","2026-07-04T12:20:21.543+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fnorth-korean-hackers-publish-108.html","north-korean-hackers-publish-108-malicious-packages-and-extensions-in-polinrider-6e9f51","North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[50,56,61],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"7fe814f9-7f4a-4e9b-9376-8c9a98a07a40","2026-07-06","morning","ThreatNoir Morning Brief — July 6","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-06\u002Fthreatnoir-morning-brief-2026-07-06.mp3",{"id":57,"date":58,"edition":53,"title":59,"audio_url":60},"ea21f9f0-a10d-4e39-8e1e-3f1871a22202","2026-07-05","ThreatNoir Weekend Brief — July 5","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-05\u002Fthreatnoir-morning-brief-2026-07-05.mp3",{"id":62,"date":63,"edition":64,"title":65,"audio_url":66},"2f511c5e-ad88-48d0-97e2-30ae28e25766","2026-07-04","afternoon","ThreatNoir Weekend Brief — July 4","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-07-04\u002Fthreatnoir-afternoon-brief-2026-07-04.mp3"]