$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
2026-04-05T19:24:08Z•64605bd83399e2aac6ab8377136a7d8a1a630e65331b529c4b787a1bf07a3ef1
Cisco-IMCDPRKDeFiDriftFortiClient-EMSReact2ShellSolanaUNC1069mobile-malwarenpmphishingsocial-engineeringsupply-chainweb-shellszero-day
What happened
The feed highlights a wave of high-impact incidents and active exploits across multiple ecosystems. Key stories: a DPRK-linked six-month social engineering operation drained $285M from Solana DEX Drift; Google and others attribute the Axios npm supply-chain compromise to North Korean UNC1069; researchers found 36 malicious npm packages abusing Redis/PostgreSQL to deploy persistent implants; and multiple actively exploited vulnerabilities were patched — Fortinet FortiClient EMS (CVE-2026-35616), Cisco IMC (CVE-2026-20093), and a Chrome/Dawn zero-day (CVE-2026-5281). Large-scale abuse of React2s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 64605bd83399e2aac6ab8377136a7d8a1a630e65331b529c4b787a1bf07a3ef1
- Enrichment time
- 2026-04-05T19:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.