North Korean Hackers Breach Go and PHP Package Repositories

Researchers have identified a campaign by North Korean hackers targeting software packages. The attackers compromised repositories used for the Go programming language.

Researchers have identified a campaign by North Korean hackers targeting software packages. The attackers compromised repositories used for the Go programming language. They also breached packages written in PHP, affecting the open‑source ecosystem. The intrusion could allow malicious code to be distributed to developers. Security analysts warn that supply‑chain attacks pose significant risks. The compromised packages were reportedly published before the breach was detected. Mitigation steps include auditing dependencies and updating affected modules. Authorities are monitoring the activity for further attribution and response.