Malware
Beavertail
Indicators of Compromise 47
Domain bitbucket[.]org Domain jsonkeeper[.]com Filename raw.js Filename test.list GitHub Repo OpenSourceMalware GitHub Repo marketfront SHA-256 0904eff1edeff4b6eb27f03e0ccc759d6aa8d4e1317a1e6f6586cdb84db4a731 SHA-256 51ddd8f6ff30d76de45e06902c45c55163ddbec7d114ad89b21811ffedb71974 SHA-256 6a9b4e8537bb97e337627b4dd1390bdb03dc66646704bd4b68739d499bd53063 SHA-256 72ebfe69c69d2dd173bb92013ab44d895a3367f91f09e3f8d18acab44e37b26d SHA-256 77aec48003beeceb88e70bed138f535e1536f4bbbdff580528068ad6d184f379 SHA-256 83c145aedfdf61feb02292a6eb5091ea78d8d0ffaebf41585c614723f36641d8 SHA-256 8efa928aa896a5bb3715b8b0ed20881029b0a165a296334f6533fa9169b4463b SHA-256 9e65de386b40f185bf7c1d9b1380395e5ff606c2f8373c63204a52f8ddc01982 SHA-256 a6914ded72bdd21e2f76acde46bf92b385f9ec6f7e6b7fdb873f21438dfbff1d SHA-256 caad2f3d85e467629aa535e0081865d329c4cd7e6ff20a000ea07e62bf2e4394 SHA-256 d27c9f75c3f1665ee19642381a4dd6f2e4038540442cf50948b43f418730fd0a SHA-256 d89c45d65a825971d250d12bc7a449321e1977f194e52e4ca541e8a908712e47 SHA-256 dff2a0fb344a0ad4b2c129712b2273fda46b5ea75713d23d65d5b03d0057f6dd SHA-256 f08e3ee84714cc5faefb7ac300485c879356922003d667587c58d594d875294e IP 135[.]181[.]123[.]177 IP 138[.]201[.]50[.]5 IP 142[.]93[.]211[.]30 IP 144[.]172[.]112[.]50 IP 144[.]172[.]96[.]35 IP 172[.]86[.]113[.]12 IP 172[.]86[.]73[.]46 IP 172[.]86[.]88[.]188 IP 216[.]126[.]236[.]244 IP 23[.]227[.]202[.]244 IP 95[.]164[.]17[.]24 Package bcrypts-js Package blockscan-api Package events-runtime Package express-session-js Package node-nvm-ssh Package npm:rollup-polyfill Package o3forms Package passports-js Package quirky-token Package react-icon-svgs Package rollup-packages-polyfill-core Package rollup-plugin-polyfill-connect Package rollup-runtime-polyfill-core Package security-alerts-sdk Package swift-parse-stream Registry User marketfront
MITRE ATT&CK TTPs 20
T1003 T1005 T1027 T1056.001 T1056.002 T1059.001 T1059.007 T1071 T1071.001 T1071.003 T1082 T1083 T1113 T1114 T1123 T1195.002 T1482 T1490 T1555 T1566
OS Credential Dumping
Credential Access
Data from Local System
Collection
Obfuscated Files or Information
Defense Evasion
Keylogging
Collection
GUI Input Capture
Collection
PowerShell
Execution
JavaScript
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Mail Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Screen Capture
Collection
Email Collection
Collection
Audio Capture
Collection
Compromise Software Supply Chain
Initial Access
Domain Trust Discovery
Discovery
Inhibit System Recovery
Impact
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Source Articles
Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview | Datadog Security Labs
In September 2024, Datadog Security Research identified three malicious npm packages—passports-js, bcrypts-js, and blockscan-api—linked to the DPRK-associated threat actor 'Tenacious Pungsan'. These packages distributed BeaverTail, a JavaScript infostealer and downloader used in the Contagious Interview campaign targeting US tech job-seekers. The malware steals cryptocurrency wallet data, browser credentials, and deploys a second-stage Python backdoor called InvisibleFerret. The activity is tied to known infrastructure and overlaps with prior Contagious Interview TTPs, indicating ongoing targeting of developers.
Datadog Security Labs
BeaverTail and OtterCookie evolve with a new Javascript module
Cisco Talos identified a new attack campaign linked to the DPRK-aligned threat group Famous Chollima, which uses social engineering through fake job offers to distribute trojanized Node.js applications. The campaign leverages malicious npm packages like 'node-nvm-ssh' and combines the BeaverTail and OtterCookie malware tools to steal credentials, cryptocurrency wallets, and system information. Recent evolution includes merged functionality between BeaverTail and OtterCookie, with new capabilities such as keylogging, screenshot capture, and clipboard monitoring delivered via a modular JavaScript-based framework.
talos
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
North Korean threat actors have been linked to a software supply chain attack involving malicious npm packages that impersonate legitimate Rollup polyfill tools. The packages, such as 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core', install secondary-stage malicious dependencies to steal developer secrets and enable remote access. The malware evades analysis environments, exfiltrates credentials, and supports interactive command execution, targeting developer workstations and CI/CD systems. This activity mirrors previous Lazarus-linked campaigns exploiting npm for credential theft.
hacker-news ·2mo ago
North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign
North Korean threat actors associated with the Contagious Interview campaign have launched the PolinRider operation, distributing 108 malicious packages and browser extensions across npm, Packagist, Go, and Google Chrome. The attack targets developers in the cryptocurrency sector through social engineering, compromising maintainer accounts to inject obfuscated JavaScript payloads into legitimate repositories. These payloads deliver second-stage malware such as DEV#POPPER RAT and OmniStealer by leveraging blockchain infrastructure and malicious VS Code task files, while using Git history manipulation to evade detection.
hacker-news ·2mo ago