Find notable cyber news and cases, enriched with sources, timelines, and signals.

North Korea-aligned developer-targeting operations shift from fake interviews to recruitment phishing at scale

Threat Actor Meta
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

North Korea-aligned developer-targeting operations are shifting from fake interviews to recruitment-themed phishing at scale, increasing the risk of industrialized credential and wallet theft across developer communities. The change indicates a more automated and scalable adversary operating model built around malicious GitHub repositories and code-review lures.

Related Happenings

GitHub API enumeration campaign targeting corporate organizations

Campaign
H score17 First: 09.07.2026 21:38 Last: 09.07.2026 21:38 Sources 1

About this happening: A GitHub API reconnaissance campaign is systematically mapping corporate organizations, repositories, and user accounts across multiple companies, expanding the risk of fo...

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....

PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret

Campaign
H score9 First: 23.06.2026 11:54 Last: 23.06.2026 11:54 Sources 1

About this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

JetBrains Marketplace malicious plugins exfiltrating AI provider keys

Malware Activity
H score12 First: 17.06.2026 12:38 Last: 17.06.2026 12:38 Sources 1

About this happening: A JetBrains Marketplace malware operation has pushed 15 malicious plugins that pose as AI coding assistants and steal AI provider API keys from developers. The plugins...

Timeline

  1. 15.06.2026 22:32 2 articles · 1mo ago

    Proofpoint links UNK_DeadDrop to recruitment phishing and malicious GitHub repositories

    Initial Disclosure

    Proofpoint reported the UNK_DeadDrop campaign targeting nearly 100 organizations with recruitment-themed phishing emails that linked to actor-controlled GitHub repositories and used VS Code projects with runOn: folderOpen to execute malicious code when opened. The infection chain delivered cross-platform loaders for macOS, Linux, and Windows, including Overlord, with the goal of stealing credentials and wallet data from developer systems.

    Show sources