Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
ClickFake Interview is a threat cluster tracked by Sekoia, associated with North Korea-aligned actors. It uses ClickFix-like lures to deceive targets into…
State-sponsored threat actors from North Korea (DPRK) are known for sophisticated cyber operations targeting cryptocurrency, defense, and technology sectors. This campaign uses…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
Sekoia is a cybersecurity company that monitors and analyzes cyber threats, including state-sponsored groups. They track the ClickFake Interview cluster associated with…