North Korea-linked Attack Exploits npm Supply Chain via Hugging Face Malware
North Korean state-sponsored hackers have weaponized Hugging Face’s ML model hosting to deploy second-stage malware via npm packages, exploiting post-install hooks to evade detection. The attack chain targets developers using ... Read More