Novel DPRK stager using Pastebin and text steganography
ID: 9ac604ad-c6b9-56e9-89e3-a228b57678ef
STIX ID: report--9ac604ad-c6b9-56e9-89e3-a228b57678ef
Feed Name: KMsec blog
### Executive summary Security researcher identified 17 malicious npm packages used by FAMOUS CHOLLIMA that embed an identical obfuscated JavaScript loader executed at install time; the loader fetches Pastebin posts, decodes a steganographic C2 list, and then pulls platform-specific remote payloads (Linux/macOS/Windows) from Vercel-hosted endpoints, enabling remote code execution. The report provides package names, a file SHA256, Pastebin links, decoded C2 domains, next-stage payload hashes, and concise hunting indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
