logo

North Korean Hackers Targeting Developers with Malicious npm Packages

ID: 357a9b7f-991f-5069-b0d6-c88048dc22c9

STIX ID: report--357a9b7f-991f-5069-b0d6-c88048dc22c9

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A set of malicious npm packages (execution-time-async, data-time-utils, login-time-utils, mongodb-connection-utils, mongodb-execution-utils and others) impersonated legitimate Node.js libraries to deliver obfuscated JavaScript that downloads next-stage payloads: a cryptocurrency and credential stealer, a Python-based browser password stealer, and an AnyDesk installer; Phylum links the campaign to North Korean state-sponsored actors (overlap with BeaverTail / Contagious Interview) and provides IOCs including package names, download counts, IP addresses (162.218.114.83 / 45.61.169.99), GitHub account names, and file paths used by the malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.