started · updated
North Korean Hackers Target macOS Users and Open‑Source npm Packages
North Korean‑linked threat actors have carried out multiple cyber campaigns. One campaign uses a fake macOS update screen to lure victims into pasting a copied Terminal command (a technique known as ClickFix). The command installs a Node.js backdoor that contacts Ethereum smart contracts for command‑and‑control (EtherHiding), steals data from browsers, targets 157 cryptocurrency wallets and deploys a malicious Chrome extension that drains the wallets.
A separate supply‑chain campaign compromised four widely used npm packages – typo‑crypto, debug, chalk and axios – by hijacking maintainer accounts and publishing malicious updates. The compromised axios package alone receives more than 100 million weekly downloads. Automated updates can pull the poisoned code into thousands of downstream systems, and research estimates that roughly one in ten cloud environments could be affected within two hours of a malicious update. The attacks are attributed to a North Korean group tracked as Sapphire Sleet, UNC1069 and related aliases. The campaigns demonstrate the use of social engineering, AI‑generated code and blockchain‑based infrastructure to steal cryptocurrency, developer credentials and potentially gain broad access to cloud environments.
Entities
Amazon Threat Intelligence · Amazon Web Services · Axios · Axios JavaScript library · Ethereum · Ethereum blockchain · North Korean state‑sponsored hacking group (Sapphire Sleet/UNC1069) · North Korean state‑sponsored hacking groups · North Korean threat actors · axios (npm package) · chalk (npm package) · debug (npm package)
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The macOS campaign employed blockchain‑hosted command‑and‑control via Ethereum smart contracts (EtherHiding). bitnewsbot.com · cybersecuritynews.com
- [● 2 SOURCES] Approximately one in ten cloud environments can be affected within two hours of a poisoned npm package update. cybersecuritynews.com · dev.to
- [○ 1 SOURCE] A Rust‑based macOS malware called Gaslight embeds 38 adversarial prompt‑injection strings to evade AI triage tools. flagthis.com
- [● 4 SOURCES] The compromised axios package receives more than 100 million weekly downloads. www.opensourceforu.com · www.clubic.com · cyberscoop.com · cybersecuritynews.com
- [● 6 SOURCES] North Korean‑linked hackers compromised four npm packages (typo‑crypto, debug, chalk, axios) between March 2025 and March 2026. cybersecuritynews.com · www.opensourceforu.com · www.clubic.com · www.theregister.com · cyberscoop.com · +1 more
- [○ 1 SOURCE] North Korean hackers used a fake macOS update screen to trick users into running malicious Terminal commands. bitnewsbot.com
- [● 2 SOURCES] The macOS attack installed a malicious Chrome extension that drains cryptocurrency wallets. bitnewsbot.com · cybersecuritynews.com
- [● 5 SOURCES] The attacks are attributed to a North Korean group tracked as Sapphire Sleet, UNC1069 and related aliases. www.opensourceforu.com · www.clubic.com · cyberscoop.com · www.theregister.com · cybersecuritynews.com
- [○ 1 SOURCE] The campaign targets 157 cryptocurrency wallets. bitnewsbot.com
- [● 2 SOURCES] The fake macOS update copies a curl command to the clipboard and prompts the user to paste it into Terminal (ClickFix). bitnewsbot.com · cybersecuritynews.com