Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees

North Korean hackers are targeting employees at technology firms with repository invitations and malicious NPM packages.

A North Korean threat actor has been observed targeting employees at technology firms in a new low-volume social engineering campaign, Microsoft-owned code hosting platform GitHub reports.

As part of the observed attacks, employees are invited to collaborate on GitHub repositories that contain software fetching malicious NPM packages meant to infect the intended victims’ computers with additional malware.

“Many of these targeted accounts are connected to the blockchain, cryptocurrency, or online gambling sectors. A few targets were also associated with the cybersecurity sector. No GitHub or npm systems were compromised in this campaign,” the code hosting platform says.

GitHub is confident that the ongoing campaign is perpetrated by a North Korean threat actor tracked as Jade Sleet, and which is also known as TraderTraitor.

To orchestrate the attacks, Jade Sleet impersonates a developer or recruiter, creating fake persona accounts on GitHub, LinkedIn, Slack, and Telegram, or taking control of legitimate accounts.

These accounts are then used to contact employees at tech firms, which are invited to collaborate on a repository. The threat actor then convinces the victim to clone the repository and execute it on their machine, leading to malware infection.

Advertisement. Scroll to continue reading.

“The threat actor often publishes their malicious packages only when they extend a fraudulent repository invitation, minimizing the exposure of the new malicious package to scrutiny,” GitHub explains.

In some cases, messaging services or file sharing platforms may be used to deliver the malicious packages and initiate the infection chain.

GitHub says it has suspended the NPM and GitHub accounts associated with the attacks and also filed abuse reports for the identified domains that were still available.

Previous iterations of the TraderTraitor campaign JavaScript applications leveraging Node.js and the Electron framework were used to infect victims with the Manuscrypt RAT.

Similar activity was reported by Phylum in late June and by SentinelOne on Thursday, in association with the recent cyberattack on JumpCloud.

Related: US, South Korea Detail North Korea’s Social Engineering Techniques

Related: US Sanctions North Korean University for Training Hackers

Related: North Korean Hackers Target Mac Users With New ‘RustBucket’ Malware

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.