UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles
2026-04-04T20:51:41Z•237c2867d58828d58dba9d2387918460dc4c1c48c5e3744679e863d512c82fc7
AWSChatGPTChrome extensionGitHub espionageLinkedInLiteLLMMercorNode.jsNorth KoreaSalesforceShinyHuntersSlackStorm infostealerUNC1069VBS backdoorWhatsApp attachmentsWindows malwareYurei ransomwaredata exfiltrationdata leakfake profilesinfostealermalicious browser extensionopen source compromisesupply chain attack
What happened
Multiple high-impact incidents and campaigns reported: North Korean actor UNC1069 is targeting Node.js maintainers via fake LinkedIn and Slack profiles to enable open-source supply-chain compromise; a malicious Chrome extension impersonating a ‘ChatGPT Ad Blocker’ was harvesting user conversations; FortiGuard-linked North Korean GitHub espionage against South Korean firms was uncovered. Separately, AI firm Mercor confirmed a breach tied to a LiteLLM supply-chain incident with attackers claiming ~4 TB stolen, and ShinyHunters claim theft of 3M+ Cisco records via Salesforce/AWS. Microsoft warned
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 237c2867d58828d58dba9d2387918460dc4c1c48c5e3744679e863d512c82fc7
- Enrichment time
- 2026-04-04T20:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.