As cited
Copy frozen at (site build).
threat intel
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
Void Dokkaebi conducts a campaign that leverages fake job interview lures to compromise developer repositories and distribute malware through trusted code workflows. The attack chain exploits organizational codebases and open-source projects to scale from individual developer compromises into supply chain risks affecting multiple downstream consumers.
Why it matters: Development teams and security practitioners responsible for code repository security, dependency management, and supply chain defense need to assess their organization's susceptibility to repository compromise and implement controls over workflow execution and third-party code integration.
- Source published
- First seen by Cybersecurity Tracker