New ‘StegaBin’ Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer
ID: a6932942-17ac-5dc2-a490-1ef9826e421e
STIX ID: report--a6932942-17ac-5dc2-a490-1ef9826e421e
Feed Name: cybersecurityNews.com
A supply-chain campaign dubbed “StegaBin” published 26 malicious npm packages that execute hidden install scripts during dependency installation to decode Pastebin-hosted steganographic payloads, contact Vercel-hosted domains for a shell, install a remote-access trojan (observed connecting to 103.106.67.63:1244), and deploy modules to exfiltrate SSH keys, Git data, browser credentials, VSCode settings, and other developer secrets; persistence includes a VSCode tasks.json trick that runs on folder open. The report includes IOCs (loader path vendor/scrypt-js/version.js, Pastebin and *.vercel.app traffic, C2 IP), links the tradecraft to North Korea-aligned activity, and provides mitigation advice such as disabling lifecycle scripts, pinning dependencies, hunting for the loader path, rotating exposed credentials, and scanning for malicious VSCode tasks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
