logo

First instance of PylangGhost RAT observed on npm

ID: 938952c3-44aa-59b6-91b7-1c4b006ba729

STIX ID: report--938952c3-44aa-59b6-91b7-1c4b006ba729

Feed Name: KMsec blog

Threat Score
88/100

Date Published: 2026-03-13

Date Updated: 2026-04-19

...
...

This report documents discovery of PylangGhost RAT (attributed to DPRK FAMOUS CHOLLIMA) being distributed through malicious npm packages in Feb–Mar 2026. The author includes the decoded loader and a refactored JavaScript sample showing a chunked downloader, ZIP extraction and execution behavior, and provides IOCs (c2 domain malicanbur.pro, IP 173.211.46.22:8080 and a VirusTotal sample hash).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.