🚨 The bait? Fake coding assignments.

North Korean hackers pushed 67 new malware-laced npm packages—over 17K downloads already.

They’re now using a stealthier loader called XORIndex to hijack dev machines, steal crypto, and drop Python backdoors.

CheckDot is SAFU research on CheckDot