The Cybersecurity Trust Reality in 2026
2026-04-01T20:51:42Z•4450b24af1b1f74059ccb3aa57f8335614208a37154141294ed4f844c5393ff5
AxiosNICKEL_ALLEYNorth KoreaRMMSTAC6405advisorycryptocurrency-theftdeveloper-targetinginfostealermalwarenpmphishingsocial-engineeringsupply-chainthreat-research
What happened
Collection of Sophos threat research and advisory posts (Mar 2026) highlighting multiple active supply-chain and social-engineering threats: a compromised Axios npm package used to deploy malware (npm package compromise/supply-chain), a phishing campaign that led to Remote Monitoring & Management (RMM) installations and observed infostealer activity (tagged STAC6405) possibly indicating experimentation or access-as-a-service, and the NICKEL ALLEY campaign using fake companies, jobs, and code repositories to target software developers and steal cryptocurrency (attributed to North Korea-themed T
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 4450b24af1b1f74059ccb3aa57f8335614208a37154141294ed4f844c5393ff5
- Enrichment time
- 2026-04-01T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.