logo

Exposed DPRK reference malware and logs

ID: c2cd1bc1-b493-51d2-b48c-8125fe4b908f

STIX ID: report--c2cd1bc1-b493-51d2-b48c-8125fe4b908f

Feed Name: KMsec blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-19

...
...

The author documents two accidental exposures by FAMOUS CHOLLIMA: an exposed JavaScript development sample (ordinary.txt) found in multiple npm packages that reveals testing practices and local payload server usage, and an err.log file from a malicious package showing a Windows username (dvant) and local file paths. These findings highlight a supply-chain malware campaign distributing obfuscated postinstall payloads via npm and reveal operator OPSEC failures useful for detection and attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.