TI Mindmap HUB
Threat Intelligence Report

North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads

📅 April 8, 2026 📰 socket.dev 🔍 0 CVE(s) referenced

North Korean threat actors have launched a prolific cross-ecosystem supply chain attack, publishing over 1,700 malicious packages to npm, PyPI, Go Modules, crates.io, and Packagist that impersonate developer tools to covertly deliver staged RAT malware, steal credentials and cryptocurrency wallets, and enable deep remote access into compromised developer environments.

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle