Cybercrime

GitHub Warns of North Korean Social Engineering Attacks Targeting Tech Firm Employees

North Korean hackers are targeting employees at technology firms with repository invitations and malicious NPM packages.

North Korean hackers are targeting employees at technology firms with repository invitations and malicious NPM packages.

A North Korean threat actor has been observed targeting employees at technology firms in a new low-volume social engineering campaign, Microsoft-owned code hosting platform GitHub reports.

As part of the observed attacks, employees are invited to collaborate on GitHub repositories that contain software fetching malicious NPM packages meant to infect the intended victims’ computers with additional malware.

“Many of these targeted accounts are connected to the blockchain, cryptocurrency, or online gambling sectors. A few targets were also associated with the cybersecurity sector. No GitHub or npm systems were compromised in this campaign,” the code hosting platform says.

GitHub is confident that the ongoing campaign is perpetrated by a North Korean threat actor tracked as Jade Sleet, and which is also known as TraderTraitor.

To orchestrate the attacks, Jade Sleet impersonates a developer or recruiter, creating fake persona accounts on GitHub, LinkedIn, Slack, and Telegram, or taking control of legitimate accounts.

These accounts are then used to contact employees at tech firms, which are invited to collaborate on a repository. The threat actor then convinces the victim to clone the repository and execute it on their machine, leading to malware infection.

Advertisement. Scroll to continue reading.

“The threat actor often publishes their malicious packages only when they extend a fraudulent repository invitation, minimizing the exposure of the new malicious package to scrutiny,” GitHub explains.

In some cases, messaging services or file sharing platforms may be used to deliver the malicious packages and initiate the infection chain.

GitHub says it has suspended the NPM and GitHub accounts associated with the attacks and also filed abuse reports for the identified domains that were still available.

Previous iterations of the TraderTraitor campaign JavaScript applications leveraging Node.js and the Electron framework were used to infect victims with the Manuscrypt RAT.

Similar activity was reported by Phylum in late June and by SentinelOne on Thursday, in association with the recent cyberattack on JumpCloud.

Related: US, South Korea Detail North Korea’s Social Engineering Techniques

Related: US Sanctions North Korean University for Training Hackers

Related: North Korean Hackers Target Mac Users With New ‘RustBucket’ Malware

Related Content

Malware & Threats

Hackers pushed a poisoned arrayref version that added a dependency to fetch a malicious payload from a remote server.

Vulnerabilities

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

Supply Chain Security

The PolinRider campaign has compromised more than 100 legitimate open source packages and repositories to deliver a backdoor and information stealer to developers.

Supply Chain Security

A malicious dependency the attackers added to over 140 Mastra packages fetches a payload targeting cryptocurrency extensions.

Email Security

The threat actor infected victims with the Snow malware family – Snowbelt, Snowglaze, and Snowbasin – for persistent access.

Nation-State

The campaigns focus on financial organizations, including cryptocurrency, venture capital, and blockchain entities.

Cybercrime

The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure.  

Cybercrime

Kejia Wang and Zhenxing Wang compromised the identities of dozens of US persons to help land jobs at over 100 companies.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version