FR
live
tag

#npm

North Korea’s WaterPlum campaign infected 30,000 devices and stole $10.7 million through fake job interviews

On September 18, 2026, a joint advisory from the FBI, Japan’s police, and several agencies revealed that WaterPlum, a North Korean group, infected more than 30,000 devices across 100-plus countries and siphoned $10.7 million in cryptocurrency through fake job interviews and poisoned repositories. Verify contractor identities and limit their access to source code and credentials.

Trojanized npm packages ship RedC2 4.0, a Linux backdoor with an AI-assisted C2

On August 20, 2026, Trend Micro disclosed fourteen functional npm packages that drop RedShell, the Linux beacon of the RedC2 4.0 C2 framework, with no install hook and no exported function call. Audit your transitive dependencies and recent package additions before a single import compromises your servers.

ChainDrop infects 1,300 npm packages and 2 billion monthly downloads

A self-propagating supply-chain attack named ChainDrop compromised over 1,300 packages on the npm registry on August 4, 2026. The infected packages accounted for 2 billion monthly downloads and reached organizations including Deliveroo, Qlik, and ServiceTitan. Audit your dependencies now.

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss