logo

New ‘StegaBin’ Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer

ID: a6932942-17ac-5dc2-a490-1ef9826e421e

STIX ID: report--a6932942-17ac-5dc2-a490-1ef9826e421e

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-03

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A supply-chain campaign dubbed “StegaBin” published 26 malicious npm packages that execute hidden install scripts during dependency installation to decode Pastebin-hosted steganographic payloads, contact Vercel-hosted domains for a shell, install a remote-access trojan (observed connecting to 103.106.67.63:1244), and deploy modules to exfiltrate SSH keys, Git data, browser credentials, VSCode settings, and other developer secrets; persistence includes a VSCode tasks.json trick that runs on folder open. The report includes IOCs (loader path vendor/scrypt-js/version.js, Pastebin and *.vercel.app traffic, C2 IP), links the tradecraft to North Korea-aligned activity, and provides mitigation advice such as disabling lifecycle scripts, pinning dependencies, hunting for the loader path, rotating exposed credentials, and scanning for malicious VSCode tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.