logo

Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview

ID: c4619ea0-5a29-5a75-80df-f116c7047053

STIX ID: report--c4619ea0-5a29-5a75-80df-f116c7047053

Feed Name: Datadog Security Labs

Threat Score
80/100

Date Published: 2024-10-24

Date Updated: 2026-04-27

...
...

Datadog Security Research identified three namesquatting npm packages (passports-js, bcrypts-js, blockscan-api) that delivered BeaverTail JavaScript infostealer variants tied to a DPRK-aligned threat actor called "Tenacious Pungsan" and the Contagious Interview campaign; the malware collects cryptocurrency wallet and browser/keychain credentials and fetches a second-stage InvisibleFerret backdoor from C2 infrastructure (95.164.17.24). The packages were downloaded a combined 323 times, have been removed and published to Datadog's malicious package dataset, and GitHub Security Advisories were released for the affected packages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.