logo

North Korean Hackers Target Windows Users with Malicious NPM Packages

ID: a16cd7e2-f050-5269-b894-5fc033f0f6ce

STIX ID: report--a16cd7e2-f050-5269-b894-5fc033f0f6ce

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2024-08-06

Date Updated: 2026-04-22

Author: do son

...
...

On July 7, researchers at Datadog identified two malicious npm packages (harthat-hash v1.3.3 and harthat-api v1.3.1) that used install scripts to download and execute a DLL via rundll32.exe, delete evidence, and exfiltrate credentials and API keys; the packages contained links to C2 domains and reused code from node-config with malicious modifications. The activity is linked to a DPRK-aligned cluster tracked by Microsoft as MOONSTONE SLEET and by Datadog as “Stressed Pungsan.” Developers are advised to check for these packages, rotate credentials, isolate affected applications, and investigate lateral movement and credential compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.