In June 2023, Phylum was the first to unearth a series of suspicious npm publications belonging to what appeared to be a highly targeted attack. The identified packages, published in pairs, required installation in a specific sequence, subsequently retrieving a token that facilitated the download of a final malicious payload from a remote server. A recent security alert from GitHub publicly attributes this cyber-attack—which they were investigating independently—to threat actors with strong ties to North Korean objectives. The GitHub Security AlertOn July 18, 2023 GitHub posted a security alert on their blog, sharing further insights into this attack, which they had been collaboratively investigating with npm, their subsidiary. They described it as a "low-volume social engineering campaign that targets the personal accounts of employees of technology firms." Additionally, they went on to say the following, We assess with high confidence that this campaign is associated with a group operating in support of North Korean objectives, known as Jade Sleet by Microsoft Threat Intelligence and TraderTraitor by the U.S
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A nonprofit security organization that collects and shares threat data to make the Internet more secure.
ZoomEye is an advanced cyberspace search engine that provides detailed information on cyberspace assets, including server software and version information, for cybersecurity experts, researchers, and enterprises.
An all-in-one email outreach platform for finding and connecting with professionals, with features for lead discovery, email verification, and cold email campaigns.
A project that detects malicious SSL connections by identifying and blacklisting SSL certificates used by botnet C&C servers and identifying JA3 fingerprints to detect and block malware botnet C&C communication.
The Trystero Project is a threat intelligence platform that measures email security efficacy and provides various tools and resources, while VMware Carbon Black offers endpoint protection and workload security solutions.
VX-Underground is a vast online repository of malware samples, featuring various collections for cybersecurity professionals and researchers to analyze and combat cyber threats.
A project sharing malicious URLs used for malware distribution to help protect networks.
FraudGuard is a service that provides real-time internet traffic analysis and IP tracking to help validate usage and prevent fraud.
A community-driven public malware repository providing access to malware samples, tools, and resources for the cybersecurity community.