North Korean Hackers Compromise Widely Used Software in Supply Chain Attack
Summary
North Korean hackers compromised a widely used software package in a supply chain attack, potentially affecting multiple sectors and aiming to steal cryptocurrency to fund the regime.
Key Points
- North Korean hackers planted a bug in a widely used software package affecting multiple American companies.
- The attack is part of a long-term campaign to steal cryptocurrency to fund North Korea's nuclear and missile programs.
- Hackers gained control of a developer's account managing the Axios open-source software and pushed a malicious update.
- Approximately 135 devices across 12 companies are initially reported affected, with more victims expected.