# Socket Weekly: North Korea-linked operators planted malware…

Canonical: https://brew.new/templates/socket/socket-weekly-north-korea-linked-operators-planted-malware

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: North Korea-linked operators planted malware…](https://cdn.brew.new/email-preview-ea2c8571e0f20c5c-tracking_r57hk9t3rmt00sd31fbpfm4ngh8f11gn-1790227270686.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

PolinRider Spreads Through Compromised GitHub Accounts and Packagist

Our research team found malicious code in the dev branches of visanduma/nova-two-factor, a Packagist package with more than 700,000 downloads, planted through a developer account the North Korea-linked operators have held since mid-June. This is the same campaign that hit npm, Go modules, and Chrome extensions earlier this year.

MORE NEWS

Google Had a Mole Inside TeamPCP

Google revealed at LABScon, in a story first reported by Wired, that Mandiant had an undercover analyst inside TeamPCP's core chat from March, which gave it access to the server where the group staged more than half a million stolen credentials. Notifying every breached company directly would have taken too long, so Google went to AWS, Microsoft, and other providers, and had the credentials revoked before the hackers could use them.

GitHub Actions Adds cache-mode to Limit Cache Poisoning Risk

GitHub shipped cache-mode, a per-workflow and per-job setting that controls whether a run can read from or write to the Actions cache, aimed at the poisoning technique behind the Ultralytics and TanStack compromises. GitHub recommends cache-mode: none for AI agent workflows, which act on issue and pull request text and can end up executing untrusted input.

MORE WORTH READING

OpenAI: Our framework for reporting model misalignment

Stage-only npm tokens for safer automation

Happy Birthday, Shai-Hulud

Google confirms Gemini models hacked three companies in May 2026

Targeted attacks on prominent Rustaceans

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/templates/socket/socket-weekly-north-korea-linked-operators-planted-malware)

[Browse email designs](https://brew.new/browse/templates)
