logo

Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators

ID: 2f0d0dd9-907e-54d4-a9c0-a2822358f610

STIX ID: report--2f0d0dd9-907e-54d4-a9c0-a2822358f610

Feed Name: KMsec blog

Threat Score
88/100

Date Published: 2026-03-17

Date Updated: 2026-04-19

...
...

This report documents the 'Contagious Trader' campaign: a highly distributed malware operation that poisons GitHub cryptocurrency trading bot projects and npm packages to steal private keys and other sensitive data, exfiltrate files to actor-controlled endpoints or databases, and establish SSH backdoors. The author enumerates multiple infection vectors (HTTP(S) endpoints, direct DB exfiltration, malicious npm postinstall scripts, and Rust variants), catalogs ~30 malicious GitHub repositories, 37 npm packages, 23 domains/IPs and other IOCs, and presents operational overlaps and infrastructure usage consistent with DPRK-linked FAMOUS CHOLLIMA activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.