# North Korean crypto hacking and software supply-chain ops

> Live situation record from CLSTR: https://clstr.news/situations/north-korean-cryptocurrency-hacking
> Updated: 2026-08-31T17:24:00.000Z. Sources: 32. Developments: 8.

By August 2026, North Korean state-sponsored actors had targeted over 1,640 organizations across 57 countries. Intelligence from Proofpoint identified the ‘UNK_DeadDrop’ cluster, which targets developers via phishing campaigns using malicious Visual Studio Code extensions (VSIX) and GitHub repositories to deploy cross-platform malware. This technical exploitation is paired with a social engineering strategy where operatives use identity theft, fraudulent banking, and artificial intelligence to impersonate foreign nationals in remote work roles.

These fraudulent schemes are expanding beyond IT into healthcare, sales, and marketing. In February 2026, three North Korean workers impersonating Chinese nationals were identified at an Australian healthcare company after investigators detected suspicious VPN usage and passport anomalies. The FBI is currently investigating a North Korean national who secured remote employment with a U.S. federal agency. Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, noted that operatives use stolen identities, fraudulent documents, and VPNs to mask their locations, sometimes utilizing US-based facilitators to receive hardware.

Financial investigations by the Royal United Services Institute (RUSI) estimate North Korea stole at least $2.8 billion in cryptocurrency between January 2024 and September 2025 to fund weapons programs. To manage these assets, Pyongyang increasingly outsources laundering to Asian criminal networks, such as ‘pig butchering’ syndicates, or sells stolen coins at a discount to third parties. This process involves mixing stolen funds with criminal proceeds and utilizing money mules in China, the Philippines, and Indonesia, alongside entities like Cambodia’s Huione Group to convert digital assets into fiat currency.

## Claims

- North Korean‑linked hackers compromised four npm packages (typo‑crypto, debug, chalk, axios) between March 2025 and March 2026. (corroborated by 6 sources)
- The attacks are attributed to a North Korean group tracked as Sapphire Sleet, UNC1069 and related aliases. (corroborated by 5 sources)
- The compromised axios package receives more than 100 million weekly downloads. (corroborated by 4 sources)
- The macOS campaign employed blockchain‑hosted command‑and‑control via Ethereum smart contracts (EtherHiding). (corroborated by 2 sources)
- The macOS attack installed a malicious Chrome extension that drains cryptocurrency wallets. (corroborated by 2 sources)
- Approximately one in ten cloud environments can be affected within two hours of a poisoned npm package update. (corroborated by 2 sources)
- The fake macOS update copies a curl command to the clipboard and prompts the user to paste it into Terminal (ClickFix). (corroborated by 2 sources)
- A Rust‑based macOS malware called Gaslight embeds 38 adversarial prompt‑injection strings to evade AI triage tools. (single source)
- The campaign targets 157 cryptocurrency wallets. (single source)

## Timeline

### 2026-08-31: North Korea expands fraudulent job schemes into healthcare and sales

North Korean actors are expanding fraudulent remote employment schemes into healthcare and sales to fund weapons programs, using forged identities and VPNs to bypass corporate security.

3 sources. https://clstr.news/cluster/north-korea-expands-fraudulent-job-schemes-into-healthcare-and-sales

### 2026-08-16: FBI investigates North Korean IT worker at US federal agency

The FBI is investigating a North Korean IT worker who infiltrated a US federal agency using false identities, highlighting growing risks of remote-work espionage and AI-enhanced recruitment fraud.

3 sources. https://clstr.news/cluster/fbi-investigates-north-korean-it-worker-at-us-federal-agency

### 2026-08-11: North Korea uses criminal networks to launder $2.8 billion in stolen crypto

North Korea stole $2.8 billion in crypto between Jan 2024 and Sept 2025, increasingly using Asian criminal networks to launder the funds to finance its weapons program.

2 sources. https://clstr.news/cluster/north-korea-uses-criminal-networks-to-launder-28-billion-in-stolen-crypto

### 2026-08-08: North Korean actors target developers and infiltrate agencies via remote work

North Korean actors are using sophisticated phishing, AI, and identity theft to secure remote jobs and fund weapons programs, including a suspected infiltration of a U.S. federal agency.

4 sources. https://clstr.news/cluster/north-korea-utilizes-cyberattacks-and-covert-it-workers-to-fund-weapons-programs

### 2026-07-29: North Korean Hackers Target macOS Users and Open‑Source npm Packages

North Korean hackers used a fake macOS update with blockchain C2 to steal crypto and deployed a malicious Chrome extension, while also compromising npm packages (typo‑crypto, debug, chalk, axios) to inject code

10 sources. https://clstr.news/cluster/north-korean-hackers-compromise-npm-packages-axios-debug-and-chalk

### 2026-07-25: North Korea arrests former military hackers accused of stealing state bank funds via cryptocurrency

North Korea arrested former military hackers on July 12, accusing them of breaching state banks and laundering stolen funds via cryptocurrency, though the claims are unverified.

5 sources. https://clstr.news/cluster/north-korea-arrests-former-military-hackers-accused-of-stealing-state-bank-funds-via-cryptocurrency

### 2026-07-23: North Korean Crypto Threats Spur Security Reveal and Arrests

Fireblocks revealed “BitForge” crypto wallet flaws that could aid nation‑state attackers like North Korea’s Lazarus group, while North Korean officials reportedly arrested a team accused of hacking state banks

6 sources. https://clstr.news/cluster/north-korean-crypto-threats-spur-security-reveal-and-arrests

### 2026-07-03: North Korea-linked hackers seize $643 million in crypto, 66% of H1 global loss

North Korean-linked hackers stole about $643 million in crypto in H1 2024, representing 66 % of the $972 million global crypto‑hacking loss, mainly from two DeFi platform breaches.

2 sources. https://clstr.news/cluster/north-korea-linked-hackers-seize-643-million-in-crypto-66-of-h1-global-loss

---
Cite as: North Korean crypto hacking and software supply-chain ops. CLSTR, https://clstr.news/situations/north-korean-cryptocurrency-hacking
