Skip to main content

Share story

Security

North Korean hackers compromised top developer to hijack widely used open source project

North Korean hackers compromised top developer to hijack widely used open source project Image: Primary
North Korean state-sponsored hackers executed a weeks-long operation to compromise a leading developer's computer and push malicious updates to one of the web's most widely used open source projects, security researchers reported Monday. The attack, attributed to the Lazarus Group or affiliated actors, involved persistent access to the developer's machine to prepare and distribute tainted code updates to the software supply chain. The compromise represents a significant escalation in North Korea's software supply chain attacks, demonstrating patience and operational security previously associated with Russian and Chinese advanced persistent threat groups. The targeted open source project, which serves millions of downstream users and applications, has not been publicly identified pending notification and remediation efforts. Security analysts said the incident highlights the vulnerability of open source maintainers, who often operate with minimal resources and security infrastructure despite their critical role in global software supply chains. The attack methodology suggests reconnaissance and preparation phases lasting several weeks before the malicious payload deployment.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from TechCrunch and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Science
AI Science

AI agents develop physical model from quantum-material observations

Researchers report in an arXiv preprint that their AI Theorist system autonomously developed a physical model explaining previously unpublished experimental observations in α-RuCl₃, a candidate material for realizing a Kitaev quan...

Security AI
Security AI

Proofpoint links TA419 phishing campaigns to US AI policy targets

Proofpoint has attributed credential phishing campaigns against U.S. AI experts at think tanks, universities and legal organizations to TA419, a group it describes as China-aligned and motivated by espionage. Its analysis describe...

Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...

Security
Security

ShinyHunters member reportedly detained in Jordan over FBI breach

ShinyHunters member Saif al-Din Khader, known as "Rey," was detained in Jordan and is cooperating to identify other hackers involved in the FBI breach, Reuters reported, citing sources. The hacking group claims to have stolen data...