logo

Novel DPRK stager using Pastebin and text steganography

ID: 9ac604ad-c6b9-56e9-89e3-a228b57678ef

STIX ID: report--9ac604ad-c6b9-56e9-89e3-a228b57678ef

Feed Name: KMsec blog

Threat Score
85/100

Date Published: 2026-02-26

Date Updated: 2026-04-19

...
...

### Executive summary Security researcher identified 17 malicious npm packages used by FAMOUS CHOLLIMA that embed an identical obfuscated JavaScript loader executed at install time; the loader fetches Pastebin posts, decodes a steganographic C2 list, and then pulls platform-specific remote payloads (Linux/macOS/Windows) from Vercel-hosted endpoints, enabling remote code execution. The report provides package names, a file SHA256, Pastebin links, decoded C2 domains, next-stage payload hashes, and concise hunting indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.