Daily brief at 7am Melbourne. Unsubscribe any time.

Sunday 5 July 2026

North Korea's Supply Chain Playbook Just Got a Lot Bigger

North Korea's PolinRider campaign seeded 108 malicious packages across npm, Go, Packagist, and Chrome — and it's still running.

Lead story

North Korea's Supply Chain Playbook Just Got a Lot Bigger

North Korea's Lazarus-linked hackers have quietly planted 108 malicious packages and Chrome browser extensions across four major software ecosystems — npm, Packagist, Go, and the Chrome Web Store — in an ongoing campaign researchers are calling PolinRider. The packages are still live, new ones are still appearing, and developers who installed any of them in the last few weeks may already be compromised.

What makes PolinRider different is the sheer breadth. Most software supply chain campaigns target a single registry — npm is the usual hunting ground. Spreading across four ecosystems simultaneously, including Go modules and a browser extension store, suggests a more mature, better-resourced operation. The threat actors aren't just dropping packages cold, either: researchers found they're also compromising legitimate maintainer accounts to push malicious updates, which is significantly harder to detect than a typosquatting package with a suspicious name.

This is connected to the Contagious Interview campaign — the same North Korean cluster that has historically posed as tech recruiters, luring developers into fake job interviews before pushing malware disguised as "take-home test" repositories. PolinRider looks like an evolution of that playbook: instead of tricking individual developers one at a time, compromise the package they already use.

Why it matters for defenders is straightforward: your Software Bill of Materials (SBOM) is only as good as the last time you checked it. A package that was clean six months ago may not be clean today if its maintainer account was compromised. Dependency pinning — locking packages to a specific, verified hash rather than a version tag — is one of the few practical defences here, alongside routine checks against databases like OSV and Socket's registry analysis.

The Chrome extension angle is particularly sharp. Extensions run in privileged browser contexts, with access to cookies, session tokens, and in many cases, all page content. A compromised extension distributed through an account takeover carries none of the usual red flags a brand-new extension might.

Australian exposure is real. The Go and npm ecosystems are deeply embedded in the technology stacks of Australian software firms, fintechs, and government digital services teams. The Australian Signals Directorate has previously warned about supply chain compromise as a top-tier threat vector in its annual Cyber Threat Reports, and the Secure Software Supply Chain principles published by ASD's ACSC directly address dependency integrity. Any Australian team with active Go or npm dependencies should be cross-referencing their lock files against the indicators of compromise Researchers have published from this campaign.

What to watch: The researchers who disclosed PolinRider flagged that new packages are likely to keep emerging. This isn't a campaign that has been shut down — it's one that has been identified. The difference matters. Threat actors with this level of persistence tend to shift tactics slightly and continue; expect updated package names and new maintainer account targets in the coming weeks.

The broader lesson isn't new but it keeps not being learned: the supply chain is the attack surface, and treating it as someone else's problem is how incidents happen.

Also today

A US Government Entity Paid $1 Million to a Group That Might Not Even Be a Ransomware Gang

A US government entity handed over roughly $1 million to a data-extortion group called Kairos to prevent stolen files from being published — but a new Ransom-ISAC case study suggests Kairos may never have deployed ransomware at all. Researchers traced the payment through blockchain records and a leaked negotiation chat, finding no evidence the group ever encrypted anything. That reframes it as pure data-theft extortion: steal files, threaten to leak, collect. No encryption required. It's a more efficient model than ransomware, with far less technical overhead — and the million-dollar payday will not go unnoticed by other threat actors looking to simplify their operations.

The Hacker News

Confidential Computing's Core Trust Mechanism Has a Flaw — and There May Be No Fix

Confidential computing is the architecture cloud providers sell as the gold standard for processing sensitive data: your workload runs in a hardware-isolated enclave that even the cloud operator supposedly can't see into. The trust anchor for that whole model is attested TLS — a handshake that proves you're talking to a genuine, unmodified enclave. The Register's deep-dive reports that attested TLS has a fundamental problem: it can't reliably prove who is on the other end of the connection in the ways the marketing claims. Researchers say the fix may not exist within the current design. For Australian organisations that have relied on confidential computing claims to satisfy Privacy Act or SOCI Act obligations around sensitive data processing, this warrants a hard look at the fine print of your cloud contracts.

The Register

Apple's Hide My Email Wasn't Actually Hiding Your Email

Apple's Hide My Email feature — part of the iCloud+ subscription that lets you create disposable relay addresses — has been quietly leaking real email addresses in certain circumstances, according to a new report. The service is supposed to be a privacy shield, generating random addresses that forward to your actual inbox while keeping your real address hidden from senders. When it fails, the downstream consequences range from embarrassing to genuinely risky: an address you handed to an untrusted service can now be matched back to your real identity. Apple has not yet commented publicly on a timeline for a fix. There are millions of iCloud+ subscribers in Australia, where privacy expectations are backed by the Privacy Act.

WIRED Security

JadePuffer: More Details on the AI-Automated Ransomware Attack

Additional technical detail has emerged on JadePuffer, the ransomware operation that researchers believe used an LLM agent to run its attack end-to-end without human direction. While Friday's Cipher lead covered the broader implications of fully autonomous ransomware, Bleeping Computer's reporting adds granularity on how the agent navigated victim environments: it made lateral-movement decisions, prioritised high-value file paths for encryption, and managed its own evasion steps. The case is still being analysed, and some researchers are debating whether the autonomy was as complete as claimed — but even a partially autonomous attack represents a meaningful shift in the operational cost of running ransomware. Defenders should revisit detection rules that assume human-paced attack timelines.

Bleeping Computer

Alibaba Bans Claude Code, Citing Security Concerns

Alibaba has reportedly classified Anthropic's Claude Code — the AI coding agent that can read, write, and execute code autonomously — as high-risk software and banned employees from using it. The reasoning, per TechCrunch, centres on data-security concerns: Claude Code, like most cloud-based AI coding tools, sends code context to external servers, raising the prospect of proprietary source code leaving the organisation. This is the same concern that caused Samsung's famous internal ChatGPT ban in 2023, now playing out at a far larger scale given how embedded AI coding tools have become. Expect more enterprise bans — or at minimum, strict approved-list policies — as security and legal teams catch up to how fast developers have adopted these tools.

TechCrunch

Midjourney Turns the Tables on Hollywood in Copyright Fight

In an ongoing legal dispute with three major Hollywood studios, AI image generator Midjourney has moved to compel the studios to disclose how they use AI tools internally. It's a classic discovery play: Midjourney is accused of training on copyrighted material, and its lawyers want to show the studios are themselves using AI in ways that complicate their clean-hands argument. The studios have not publicly confirmed the extent of their internal AI use. If the courts compel disclosure, the resulting documents could reshape how AI copyright cases are litigated — and potentially expose uncomfortable hypocrisies on both sides. Australian copyright law has similar tensions that the government's AI copyright consultation has not yet resolved.

TechCrunch

The Open Source AI Gap Map: Where Proprietary Models Still Beat Open Ones

Simon Willison has highlighted the Open Source AI Gap Map, a research resource charting the capabilities where open-weight AI models still meaningfully lag behind closed, proprietary systems. The gaps aren't where most people assume: raw benchmark performance on language tasks has largely closed, but areas like long-context reliability, multimodal reasoning, and tool-use consistency remain stubborn advantages for frontier closed models. For organisations — including Australian government agencies increasingly interested in open-weight models for sovereign AI deployments — the map is a useful reality check on where you can substitute open for closed today and where you probably can't yet.

Simon Willison

Fanfic Communities Are Waging a War on AI-Written Stories — With Flawed Weapons

The fanfiction world is in a quiet civil war. A growing movement on Archive of Our Own and related platforms is attempting to identify and expel writers using generative AI, including deploying AI-detection tools to flag suspicious works. The Verge reports the problem: AI detectors are notoriously unreliable, producing false positives that are catching human writers — particularly non-native English speakers — in the dragnet. The communities are discovering, painfully, that there is no clean technical solution to the question of authenticity. It's a small-stakes preview of a much larger problem facing every creative and professional domain grappling with AI-generated content and the absence of reliable provenance tools.

The Verge

NASA's Racing to Save a 22-Year-Old Space Telescope From Burning Up

NASA's Swift Observatory — launched in 2004 to study gamma-ray bursts and now one of the field's most productive instruments — is slowly falling out of orbit due to increased atmospheric drag from recent solar storms. Without intervention, it could re-enter the atmosphere as soon as later this year. NASA has enlisted startup Katalyst Space Technologies, whose Link spacecraft launched Friday with the goal of docking to Swift and boosting its orbit. The mission is a test case for commercial satellite-servicing technology, which could eventually be used to extend the lifespan of other ageing space assets. If it works, it's a significant proof of concept; if it doesn't, Swift becomes one of the more expensive losses in recent NASA history.

The Verge

White House Quietly Deleted 6,000 Energy Conservation Pages During a Heatwave

The US Department of Energy removed approximately 6,000 web pages related to energy conservation — guidance on home efficiency, grid management, and energy-saving tips — while a record-breaking heatwave was driving unprecedented strain on the US electricity grid. The timing followed Republican criticism of a New York City mayor who asked residents to set air conditioning to 78 degrees. Critics note that pulling practical conservation information during an active heat emergency is, at minimum, counterproductive. For tech and policy watchers, it's another data point in the ongoing pattern of federal agencies systematically removing public digital resources — a trend with downstream consequences for researchers, journalists, and the public who relied on them.

The Verge

Mistral AI: A Plain-English Primer on Europe's Biggest AI Bet

TechCrunch has published a comprehensive explainer on Mistral AI — the Paris-based lab that has become Europe's most prominent answer to OpenAI and Anthropic. Mistral has raised significant funding, released a mix of open-weight and proprietary models, and positioned itself as the frontier AI option for organisations that want a non-US provider. That sovereign-AI pitch resonates particularly in Europe, where GDPR and AI Act compliance creates real incentives to avoid US cloud dependencies — but it's increasingly relevant to Australian government and enterprise customers who are weighing where their AI infrastructure should live. Mistral's open-weight releases also sit differently under Australia's evolving AI governance framework than closed-model API services do.

TechCrunch

Sources consulted