Hackers compromised the Injective Labs SDK GitHub repository to publish a malicious npm package that steals cryptocurrency wallet private keys and seed phrases. This malware poses a direct threat to developers and users managing crypto assets.
North Korean hackers linked to the Contagious Interview campaign have published 108 malicious packages and browser extensions across multiple platforms as part of their ongoing PolinRider operation. These malicious artifacts are being actively distributed via compromised maintainer accounts on npm, Packagist, Go, and Chrome Web Store.
Microsoft has attributed the recent Mastra AI supply chain attack, compromising over 140 npm packages, to the North Korean group Sapphire Sleet, aka BlueNoroff. This highlights ongoing state-sponsored supply chain risks affecting open source ecosystems.