O
n July 31, 2026, the US and its 10 allied countries issued a unique joint warning in which they accused the IT employees of North Korea of employing forged identities and artificial intelligence technology to launch cyber attacks against hiring websites in the US, Europe, and Asia.
According to the 11 nations, the cyber attack scheme generates revenues through fake job hiring and sends all proceeds of such fraudulent activities directly towards the nuclear weapons and ballistic missile projects of North Korea.
The joint warning described a new strategy of hacking in which the IT employees of North Korea forge their identities and conduct video interviews with the help of deep fake technology to bypass the hiring verification process of companies.
On August 4, four days after release of the MSMT advisory, the North Korean Foreign Ministry published a counter-statement repudiating the claim as a "stereotypical political charge" via the state news service KCNA.
A significant escalation, compared with prior denials of involvement in cyber attacks, the response went beyond denying the accusations by singling out the Multilateral Sanctions Monitoring Team (MSMT) – the organization coordinating and releasing the advisory – as a "phantom-like mechanism which has never had a legal basis." The denunciatory statement accused the US of pursuing the "militarization of cyberspace" by way of the world's largest force of cyber troops and pointing to the existence of US Cyber Command.
In South Korean and international media coverage of the event, Pyongyang portrayed the situation entirely as an effort by the US and its partners to "damage the reputation" of North Korea, rather than addressing any of the technical claims made in the MSMT advisory.
The diplomatic response from Pyongyang is one with which it has been familiar for many years. Namely, deny the accusation outright, cite the superior cyber capabilities of the West, and avoid confronting the substantive claims made.
As far back as 2017, a North Korean deputy ambassador to the UN has responded to suggestions that North Korea may have been behind the WannaCry ransomware attack as "absurd", and cited a propaganda operation by the US and South Korea.
It is argued by analysts that this consistency of rhetoric over more than a decade's worth of attribution disputes suggests that the denials constitute a consistent diplomatic position, not an ad hoc denial based on the facts. Of particular interest to mention is that the North Korean IT workers are independently and additionally documented through US domestic law enforcement, separately from the MSMT advisory.
Eight facilitators were sentenced to federal prison terms in 2026 as part of the Justice Department's DPRK RevGen: Domestic Enabler Initiative, and the government has indicated that companies with poor compliance programs could be criminally liable should they unknowingly hire North Korean IT workers.
Even if the warning issued on July 31 was about a hiring scam and not a supply chain attack, it follows a completely separate thread that is also getting progressively worse: The North Korean government-backed cyber groups have also been associated with the attacks on the open-source npm JavaScript packages.
Earlier this year, Amazon Web Services' threat intelligence group attributed the compromise of several npm JavaScript packages – including Axios (http client), debug, chalk, and typo-crypto – to one North Korean-affiliated adversary who is known variously as Sapphire Sleet, Blue Noroff, Stardust Chollima, and APT38.
In the Axios incident, hackers hacked a package maintainer's account in March 2026 and released backdoored packages that contained a post-installation script for downloading malware on any system installing this backdoored library. With Axios being a transitive dependency of several million projects, the blast radius could be considerable.
This was by no means a one-off occurrence. A month later, the very same attacker group was responsible for another npm compromise: in June 2026, more than 140 Mastra AI npm packages were compromised within about 19 minutes after the maintainer accounts were hacked, leaving an estimated 8 million weekly downloads open to malware that was capable of stealing cryptocurrency wallets and establishing remote access.
This Sapphire Sleet attribution was confirmed by Microsoft's threat intelligence team a few days after the incident. As reported by the security experts, this was the sixth high-profile poisoning of the npm package registry in an eleven-week window, after the Bitwarden CLI, SAP Cloud Services packages, the TanStack libraries, and the other popular packages had already been compromised.
Another separate and affiliated North Korean-related group operating under the name of Team PCP was also accused of malicious injections in GitHub Actions workflows and Python's PyPi packages of such security tools as Trivy and Checkmarx.
While it may seem like the two threads under discussion involve different units of North Korean cyber capabilities and impact different victim groups, this fact alone proves one thing: North Korea's cyber organization has gone far beyond high-profile bank robberies and ransomware attacks and has begun to seek new revenue and access streams using fraud and infiltration techniques targeting employees and supply chains, whether it be through false employment offers or compromising code libraries used and trusted by developers all around the world.
According to the researchers, attribution controversies do not really matter much for the defensive purposes and are more a question of diplomacy than anything else, especially as Pyongyang keeps denying any involvement and attributions as politically motivated.
As a top manager from Amazon stated, "organizations must look at defending-in-depth techniques capable of detecting the attack vectors, regardless of who is using them."












