UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles

2026-04-04T20:51:41Z237c2867d58828d58dba9d2387918460dc4c1c48c5e3744679e863d512c82fc7
AWSChatGPTChrome extensionGitHub espionageLinkedInLiteLLMMercorNode.jsNorth KoreaSalesforceShinyHuntersSlackStorm infostealerUNC1069VBS backdoorWhatsApp attachmentsWindows malwareYurei ransomwaredata exfiltrationdata leakfake profilesinfostealermalicious browser extensionopen source compromisesupply chain attack

What happened

Multiple high-impact incidents and campaigns reported: North Korean actor UNC1069 is targeting Node.js maintainers via fake LinkedIn and Slack profiles to enable open-source supply-chain compromise; a malicious Chrome extension impersonating a ‘ChatGPT Ad Blocker’ was harvesting user conversations; FortiGuard-linked North Korean GitHub espionage against South Korean firms was uncovered. Separately, AI firm Mercor confirmed a breach tied to a LiteLLM supply-chain incident with attackers claiming ~4 TB stolen, and ShinyHunters claim theft of 3M+ Cisco records via Salesforce/AWS. Microsoft warned

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
237c2867d58828d58dba9d2387918460dc4c1c48c5e3744679e863d512c82fc7
Enrichment time
2026-04-04T20:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.