logo

North Korean “StegaBin” Campaign Targets Developers with Steganographic Malware

ID: fb74e88e-7370-5143-82f0-9915bb2b77be

STIX ID: report--fb74e88e-7370-5143-82f0-9915bb2b77be

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Socket researchers uncovered "StegaBin," a sophisticated supply-chain malware campaign by North Korean–aligned FAMOUS CHOLLIMA that used 26 malicious npm packages and character-level steganography in Pastebin essays to hide C2 addresses; the packages typosquatted popular libraries and included legitimate dependencies to avoid breaking developer projects while a nine-module toolkit harvested VSCode persistence data, SSH keys, git repos, browser credentials, clipboard contents, and crypto wallets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.