View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Amazon Links North Korean Hackers to Multiple NPM Supply Chain Attacks

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Amazon Links North Korean Hackers to Multiple NPM Supply Chain Attacks
    Amazon attributes several high-profile NPM supply chain attacks to North Korean hackers.

    • Targets: Popular Node Package Manager (npm) libraries including typo-crypto, debug, chalk, and axios
    • Attack timeline: Started March 2025 with typo-crypto, escalated in September 2025 with debug and chalk, and hit axios in March 2026
    • Attack method: Social engineering of package maintainers to publish malicious updates automatically distributed to users
    • Attribution: Linked to North Korean threat actor Sapphire Sleet (BlueNoroff, Stardust Chollima) based on tactics, infrastructure, and operational similarities
    • Attack trends: Use of multi-stage payloads, environment-aware malware, AI-assisted code generation, and squatting on AI-generated package names
      πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer
  • DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
    North Korean threat actors use fake macOS update screens to deliver crypto-stealing malware.

    • Targets macOS users via malvertising with fake full-screen update pages
    • Attack starts from clicking sponsored search results leading to fake update prompts
    • Uses clipboard-pasted Terminal commands (ClickFix technique) to execute Node.js backdoor
    • Backdoor fetches C2 server address from Ethereum smart contracts (EtherHiding)
    • Steals data from 157 cryptocurrency wallets and installs malicious Chrome extension
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Six critical vulnerabilities found in SGLang framework including unauthenticated RCE and data leaks CVE-2026-15969 CVE-2026-15971 CVE-2026-15974 CVE-2026-15976 CVE-2026-15977 CVE-2026-15978
    Multiple unauthenticated vulnerabilities in SGLang enable remote code execution, data exfiltration, and credential leaks.

    • Applies to SGLang open-source framework for serving large language and multimodal AI models
    • Includes unauthenticated remote code execution via crafted pickle payloads and insecure model weight loading
    • Server-side request forgery and local file read via unsanitized image URL input in chat completions endpoint
    • Credential leakage through /server_info endpoint exposing API keys and SSL keyfile info with admin API key
    • Model weight exfiltration possible without API keys by triggering distributed weight broadcasting endpoints
      πŸ“Ž Coverage: kb.cert.org Β· πŸ“„ Original: github.com Β· πŸ‘ via CERT/CC Vulnerability Notes, CVE ThreatInt (+5)
  • IBM Langflow OSS 1.0.0-1.10.1 vulnerable to RCE, DoS, path traversal, and data exposure
    IBM Langflow OSS versions 1.0.0 to 1.10.1 have multiple vulnerabilities allowing unauthorized data access and remote code execution.

    • Applies to IBM Langflow OSS versions 1.0.0 through 1.10.1
    • Vulnerabilities include remote code execution, denial of service, path traversal, and exposed credentials
    • Attackers can access other users' private vector documents by matching Chroma persist_directory and collection_name
    • Attackers can insert documents into victims' collections, polluting shared namespaces
    • Exploits occur via unauthenticated and insufficiently authorized API endpoints
      πŸ“Ž Coverage: cve.threatint.com Β· πŸ“„ Original: cve.threatint.com Β· πŸ‘ via CVE ThreatInt
  • Critical Arbitrary File Read and RCE in Rails Active Storage via libvips (CVE-2026-66066) CVE-2026-66066
    Rails Active Storage is vulnerable to arbitrary file read and remote code execution via crafted image uploads.

    • Applies to Rails Active Storage versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1
    • Vulnerability allows unauthenticated attackers to read arbitrary files accessible to the Rails process
    • Exploits unsafe libvips operations enabled for untrusted image uploads
    • Exposure of environment variables and secrets like secret_key_base can lead to remote code execution
    • Fixed in versions 7.2.3.2, 8.0.5.1, and 8.1.3.1
      πŸ“Ž Coverage: cve.threatint.com Β· πŸ“„ Original: cve.threatint.com Β· πŸ‘ via CVE ThreatInt

πŸ“‹ ADVISORIES

  • Multiple vulnerabilities in Google Chrome before 151.0.7922.71 allow code execution
    Multiple vulnerabilities in Google Chrome allow arbitrary code execution.

    • Applies to Google Chrome versions prior to 151.0.7922.71/.72 on Windows, Mac, and Linux
    • Multiple use-after-free, insufficient validation, and implementation flaws across components like Compositing, Dawn, Views, Skia, V8, ANGLE, and more
    • Exploitation could allow arbitrary code execution in the context of the logged-on user
    • Attack vector includes drive-by compromise via malicious web content
    • No reported exploitation in the wild as of advisory date
      πŸ“Ž Coverage: cisecurity.org Β· πŸ“„ Original: cisecurity.org Β· πŸ‘ via CIS Advisories
  • email-phishing-spf-dkim-dmarc-bypass β€” @briankrebs@infosec.exchange

  • CISA issues open-source software security guidance for federal agencies
    CISA published security guidance for federal agencies on managing open-source software risks.

    • Applies to federal agencies using open-source software (OSS)
    • Guidance covers OSS risk management, patching, and open-weight AI model security
    • Encourages evaluating OSS trustworthiness before approval and tracking OSS assets
    • Highlights unique OSS traits like transparency and collaborative maintenance
    • Addresses challenges with unverifiable AI models and recent OSS attack trends
      πŸ“Ž Coverage: cyberscoop.com Β· πŸ‘ via CyberScoop

πŸ”“ CVEs & KEV

  • CVE-2026-12943 β€” CVSS 9.8 β€” This Power Hardware Management Console update is being released to addressIBM...
  • CVE-2026-18245 β€” CVSS 9.0 β€” Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codege...
  • CVE-2026-18140 β€” CVSS 7.5 β€” Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows un...
  • CVE-2024-25039 β€” CVSS 7.5 β€” IBM Engineering Requirements Management DOORS and DOORS Web Access is affecte...
  • CVE-2026-10545 β€” CVSS 7.5 β€” IBM Planning Analytics Local is affected by Open RedirectIBM Planning Analyti...
  • CVE-2026-12733 β€” CVSS 7.5 β€” IBM DataPower Gateway affected by denial of serviceIBM DataPower Gateway coul...
  • CVE-2024-40683 β€” CVSS 6.3 β€” IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allo...
  • CVE-2025-36374 β€” CVSS 5.5 β€” IBM DataPower Gateway affected by XML external entity injectionIBM DataPower ...
  • CVE-2026-14227 β€” CVSS 4.9 β€” Insufficient session expiration in MikroTik RouterOSAn API session‑management...
  • CVE-2026-59881 β€” CVSS β€” β€” AIOHTTP: WebSocket client accepts compressed frames without negotiated permes...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check