logo

North Korean XORIndex malware hidden in 67 malicious npm packages

ID: 6efdf5b2-bcb8-5d71-a286-8c09b9ef9f1f

STIX ID: report--6efdf5b2-bcb8-5d71-a286-8c09b9ef9f1f

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-07-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

North Korean state-backed actors in the ‘Contagious Interview’ campaign uploaded 67 malicious npm packages (around 17,000 downloads) that use postinstall scripts to deploy the XORIndex loader (and previously HexEval) to profile hosts and retrieve JavaScript payloads (BeaverTail, InvisibleFerret) from a Vercel-hosted C2; these backdoors and information stealers enable persistent access and data exfiltration, and defenders are advised to vet packages, check publishers, review source code for obfuscation, and test libraries in isolated environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.