Spiking NN Lib BindsNET Compromised in DPRK Supply Chain Attack

cyb3rops · x · 2026-09-02

The open-source BindsNET library for spiking neural networks was compromised in a supply chain attack linked to the DPRK-associated NullReceiver campaign. Threat actors used a force-push with backdated commits to inject a malicious VS Code task and an obfuscated Node.js loader disguised as a Font Awesome file. Users should verify the integrity commit 780abb9d.

Original post →

More from Safety

Safety channel →