North Korean XORIndex malware hidden in 67 malicious npm packages
ID: 6efdf5b2-bcb8-5d71-a286-8c09b9ef9f1f
STIX ID: report--6efdf5b2-bcb8-5d71-a286-8c09b9ef9f1f
Feed Name: Bleeping Computer
North Korean state-backed actors in the ‘Contagious Interview’ campaign uploaded 67 malicious npm packages (around 17,000 downloads) that use postinstall scripts to deploy the XORIndex loader (and previously HexEval) to profile hosts and retrieve JavaScript payloads (BeaverTail, InvisibleFerret) from a Vercel-hosted C2; these backdoors and information stealers enable persistent access and data exfiltration, and defenders are advised to vet packages, check publishers, review source code for obfuscation, and test libraries in isolated environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
