A few days old, but what a read. A Lumma infection gave up, among others things, definitive proof of DPRK attribution for the Polyfill compromise. Also solid details on fake IT employee tradecraft.

https://www.infostealers.com/article/how-one-infostealer-infection-solved-a-global-supply-chain-mystery-and-unmasked-dprk-spies-in-u-s-crypto/