DPRK-linked threat actors are manipulating git commit timestamps to make freshly created GitHub repositories appear years old and trustworthy, hiding obfuscated malware loaders inside commonly trusted configuration files. At least one flagged repo had accumulated over 100 stars before detection. The technique is part of Pyongyang's broader developer-targeting playbook โ€” which has increasingly zeroed in on crypto and web3 engineers through fake open-source packages, fraudulent job interviews, and supply chain compromise.

TLDR by @Benthic

More coverage

Explore the topic

More on North Korea

Comments