Rust Supply Chain Attack: Malicious Crates with 245M Downloads Target Build-Time Execution
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
On August 20, 2026, the Rust Project removed malicious versions of three widely used crates from crates.io after a compromised maintainer account…
[APT38](https://attack.mitre.org/groups/G0082) is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
Microsoft assesses with high confidence that the Mastra npm compromise is attributable to Sapphire Sleet, a North Korean threat actor known for…