logo

North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT

ID: 2c411a01-f3f5-5e76-b73b-2ea2060a0d1a

STIX ID: report--2c411a01-f3f5-5e76-b73b-2ea2060a0d1a

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed a North Korean APT supply‑chain campaign (tracked as "StegaBin" / part of Contagious Interview) that published 26 typosquatting npm packages containing install-time loaders which decode Pastebin steganography to obtain Vercel-hosted C2s and deliver multi-platform credential-stealers and a RAT. The malware provides VS Code persistence, keylogging and clipboard theft, browser and crypto-wallet credential theft, TruffleHog-based secret scanning, Git/SSH exfiltration, and remote-control capabilities; infrastructure includes 31 Vercel deployments and active C2 IPs and ports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.