The Cybersecurity Trust Reality in 2026

2026-04-01T20:51:42Z4450b24af1b1f74059ccb3aa57f8335614208a37154141294ed4f844c5393ff5
AxiosNICKEL_ALLEYNorth KoreaRMMSTAC6405advisorycryptocurrency-theftdeveloper-targetinginfostealermalwarenpmphishingsocial-engineeringsupply-chainthreat-research

What happened

Collection of Sophos threat research and advisory posts (Mar 2026) highlighting multiple active supply-chain and social-engineering threats: a compromised Axios npm package used to deploy malware (npm package compromise/supply-chain), a phishing campaign that led to Remote Monitoring & Management (RMM) installations and observed infostealer activity (tagged STAC6405) possibly indicating experimentation or access-as-a-service, and the NICKEL ALLEY campaign using fake companies, jobs, and code repositories to target software developers and steal cryptocurrency (attributed to North Korea-themed T

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
4450b24af1b1f74059ccb3aa57f8335614208a37154141294ed4f844c5393ff5
Enrichment time
2026-04-01T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.