< Back to all clusters
[TECHNOLOGY] · North Korea · 10 sources

started · updated

North Korean Hackers Target macOS Users and Open‑Source npm Packages

North Korean‑linked threat actors have carried out multiple cyber campaigns. One campaign uses a fake macOS update screen to lure victims into pasting a copied Terminal command (a technique known as ClickFix). The command installs a Node.js backdoor that contacts Ethereum smart contracts for command‑and‑control (EtherHiding), steals data from browsers, targets 157 cryptocurrency wallets and deploys a malicious Chrome extension that drains the wallets.

A separate supply‑chain campaign compromised four widely used npm packages – typo‑crypto, debug, chalk and axios – by hijacking maintainer accounts and publishing malicious updates. The compromised axios package alone receives more than 100 million weekly downloads. Automated updates can pull the poisoned code into thousands of downstream systems, and research estimates that roughly one in ten cloud environments could be affected within two hours of a malicious update. The attacks are attributed to a North Korean group tracked as Sapphire Sleet, UNC1069 and related aliases. The campaigns demonstrate the use of social engineering, AI‑generated code and blockchain‑based infrastructure to steal cryptocurrency, developer credentials and potentially gain broad access to cloud environments.

Entities

Amazon Threat Intelligence · Amazon Web Services · Axios · Axios JavaScript library · Ethereum · Ethereum blockchain · North Korean state‑sponsored hacking group (Sapphire Sleet/UNC1069) · North Korean state‑sponsored hacking groups · North Korean threat actors · axios (npm package) · chalk (npm package) · debug (npm package)

Claims

What the coverage asserts, and how many sources carry each claim.