logo

Stressed Pungsan: DPRK-aligned threat actor leverages npm for initial access

ID: 40b05afc-2aa0-5fbb-abd7-38d5f0ba75f1

STIX ID: report--40b05afc-2aa0-5fbb-abd7-38d5f0ba75f1

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2024-07-31

Date Updated: 2026-04-27

...
...

Datadog Security Labs discovered two near-identical malicious npm packages that abuse npm preinstall scripts to drop a DLL from http://142.111.77.196 and execute it via rundll32, a supply-chain technique attributed to a DPRK-aligned cluster (MOONSTONE SLEET / “Stressed Pungsan”). The delivered DLL exports GenerateKey/GenerateKeyW but showed no active malicious behavior in analysis; the report includes the IP and SHA256 indicators and recommends investigation, credential rotation, and isolation if impacted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.