The bait? Fake coding assignments.

North Korean hackers pushed 67 new malware-laced #npm packages—over 17K downloads already.

They’re now using a stealthier loader called #XORIndex to hijack dev machines, steal crypto, and drop #PythonBackdoors.

Read → https://thehackernews.com/2025/07/north-korean-hackers-flood-npm-registry.html

North Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign

North Korean hackers continue attacking open-source software via npm packages. 67 new malicious packages with XORIndex Loader target developers.

The Hacker News