logo

VMWare artifacts left by a FAMOUS CHOLLIMA operator

ID: 41df5115-e320-5bd4-b8de-40c5a29bb477

STIX ID: report--41df5115-e320-5bd4-b8de-40c5a29bb477

Feed Name: KMsec blog

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-19

...
...

Researcher discovered multiple malicious npm packages (May–June 2025) attributable to DPRK-linked FAMOUS CHOLLIMA that included a Windows LNK file revealing operator telemetry (VMWare usage, shared folder mapped at \\vmware-host\\Shared Folders\\VM_Share\\Repos_paladin\\my_npm\\logs-buffer), a reused payload hash (f290db50ffe64d4fb5fe409d3d1c8eca6f6711e4bbd85a13c9dce055508cc1b3) and consistent next-stage infrastructure (log-server-lovat.vercel.app), indicating a focused supply-chain/campaign with repeatable TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.