CyberNotableSingle-source
5.5
Amazon attributes 2025 npm supply chain attack to North Korean threat actor Sapphire Sleet
The Hacker News·KP · US·about 22 hours ago
Two beta npm packages from the Joyfill library have been identified as containing malicious code that executes upon import, bypassing traditional install-hook detection. The malware utilizes a multi-blockchain retrieval mechanism to fetch a remote access trojan (RAT) linked to the DEV#POPPER threat actor, maintaining persistence beyond the initial build or test process.