North Korean Hackers Weaponize Crypto Dev Pipelines via Fake LinkedIn
A North Korean-linked hacker group is using fake LinkedIn invitations to infect crypto developers with macOS malware, then weaponizing their CI/CD pipelines to automatically spread the infection across entire teams. The attack chain exploits stolen GitHub tokens to inject malware into source code repositories, turning development infrastructure into a distribution network.









