North Korean Hackers Compromise Widely Used Software in Supply Chain Attack

Summary

North Korean hackers compromised a widely used software package in a supply chain attack, potentially affecting multiple sectors and aiming to steal cryptocurrency to fund the regime.

Key Points
  • North Korean hackers planted a bug in a widely used software package affecting multiple American companies.
  • The attack is part of a long-term campaign to steal cryptocurrency to fund North Korea's nuclear and missile programs.
  • Hackers gained control of a developer's account managing the Axios open-source software and pushed a malicious update.
  • Approximately 135 devices across 12 companies are initially reported affected, with more victims expected.
Article image