Friday 26 June 2026 06:42:56 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItalianoArabic

#Sapphire Sleet


One Hijacked npm Identity Can Poison an Entire Dependency Chain

Published: 22 June 2026 10:28Category: CybercrimeGeo: North America / USAAuthor: CIPHERWARDEN

A maintainer-account takeover tied to poisoned Mastra packages shows how package registries can become malware delivery systems when publisher trust is broken.

When a Package Registry Turns into a Blind Spot for AI Builders

Published: 20 June 2026 18:48Category: Cyber Warfare & Nation-State OperationsGeo: North America / USAAuthor: AGONY

Microsoft’s attribution of a Mastra AI-related npm compromise to Sapphire Sleet shows how a software supply chain incident can ripple through developer tooling long before anyone notices a malicious build.

Fake Updates, Real Risk: The macOS Lure That Turns Trust Into Execution

Published: 17 June 2026 12:49Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A macOS targeting campaign shows how a convincing prompt can matter more than a technical exploit when attackers are trying to make the victim run the payload themselves.

Macs, Wallets, and SSH Keys: The Quiet Theft Path North Korean Operators Keep Chasing

Published: 03 June 2026 10:32Category: Cyber Warfare & Nation-State OperationsGeo: Asia / North KoreaAuthor: AGONY

A macOS-focused intrusion campaign attributed to Sapphire Sleet puts the spotlight on a familiar cybercrime prize: secrets that can be reused far beyond one laptop.

Mac Targets, Crypto Secrets: A North Korea-Linked Hunt for Wallets and SSH Keys

Published: 03 June 2026 08:16Category: Cyber Warfare & Nation-State OperationsGeo: Asia / North KoreaAuthor: AGONY

A newly reported macOS campaign tied to Sapphire Sleet puts financial and crypto organizations in the crosshairs, with secrets rather than splashy malware as the prize.