Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: hacker-news Clear filter
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

1mo ago · hacker-news

North Korean threat actors associated with the Contagious Interview campaign have launched the PolinRider operation, distributing 108 malicious packages and browser extensions across npm, Packagist, Go, and Google Chrome. The attack targets developers in the cryptocurrency sector through social engineering, compromising maintainer accounts to inject obfuscated JavaScript payloads into legitimate repositories. These payloads deliver second-stage malware such as DEV#POPPER RAT and OmniStealer by leveraging blockchain infrastructure and malicious VS Code task files, while using Git history manipulation to evade detection.

2 IoCs 1 Malware
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

1mo ago · hacker-news

A U.S. government entity, likely Union County, Ohio, paid approximately $1 million to a threat actor named Kairos following a data theft extortion incident. Unlike traditional ransomware attacks, Kairos did not encrypt systems but instead exfiltrated sensitive data—including files from the prosecutor's office—and threatened to leak it unless paid. The attack highlights a growing trend of pure data-theft extortion, where the leverage is the threat of public data disclosure rather than encryption. The payment of 9.44 BTC was traced through blockchain to exchanges including Bybit, OKX, and the Russian service BELQI, but no confirmation of data deletion was verifiable.

1 IoCs 1 Actors
← Previous