Latest

Compromised code package spreading through connected nodes with hidden malicious link, representing AI-driven npm supply chain attack targeting developers and crypto systems.

North Korea Uses AI to Plant npm Malware via Fake U.S. Companies in Escalating Developer Campaign

North Korean threat actors have escalated their developer-targeting campaign by using an AI large language model to insert malicious npm dependencies into legitimate projects — operating through fake U.S.-registered companies and deploying full-featured remote access trojans targeting cryptocurrency wallets and developer infrastructure. GLOBAL — Cybersecurity researchers at ReversingLabs have documented