logo

Malicious NPM Packages Spread PylangGhost RAT in Supply Chain Attack

ID: c927527e-c532-5462-9a8b-cc776818d3e7

STIX ID: report--c927527e-c532-5462-9a8b-cc776818d3e7

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Malicious npm packages (react-refresh-update 1.0.1–1.0.4 and @jaime9008/math-service 1.0.1–1.0.2) were used to stage the PylangGhost Python RAT—attributed to the North Korean‑linked Famous Chollima/Lazarus ecosystem—by embedding an obfuscated JavaScript loader that decodes, XOR‑decrypts, and executes a downloader which retrieves platform‑specific archives from malicanbur.pro and connects to 173.211.46.22:8080; the campaign targets developer workstations and CI pipelines across Windows, Linux, and macOS and includes actionable IOCs and mitigation recommendations (remove/pin bad versions, block domains/IPs, hunt for start.vbs/macspatch.sh, and scan for PylangGhost modules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.