New ‘StegaBin’ Campaign Deploys Multi-Stage Credential Stealer via 26 Malicious npm Packages
ID: f626bb3e-e1f9-5680-b028-a4229437bd9c
STIX ID: report--f626bb3e-e1f9-5680-b028-a4229437bd9c
Feed Name: GBHackers
StegaBin is a supply-chain attack targeting JavaScript developers via 26 malicious npm packages (typosquatting popular libraries) that deploy a multi-stage credential stealer and RAT; the loader uses Pastebin text steganography to reveal Vercel-hosted staging domains, fetches platform-specific payloads, and installs a parser.js RAT that communicates with 103.106.67.63:1244. The toolkit includes VSCode persistence, keylogging, clipboard and browser credential theft, Git/SSH exfiltration, and redeployment for persistence, and the activity is attributed to the DPRK-aligned FAMOUS CHOLLIMA actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
