A Year-Long Campaign of North Korean Actors Targeting Developers via Malicious npm Packages

2024-08-07 Checkmarx

https://zero.checkmarx.com/a-year-long-campaign-of-north-korean-actors-targeting-developers-via-malicious-npm-packages-dbf7a6761361

Checkmarx describes a nearly year-long North Korean campaign that publishes malicious npm packages to compromise developers, with a July 2024 surge reported by multiple security firms. The packages are often short lived because the actors unpublish them quickly, erasing registry placeholders that would otherwise help researchers track names. Across samples, the malware keeps a similar flow: check the operating system, download and XOR-decrypt a payload, execute it with rundll32, and clean up traces. Recent packages mimic trusted npm projects by blending copied legitimate code with malicious functionality, while the lure set has shifted from fake job interviews to other development-workflow pretexts.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 142.111.77.196 2024-08-01 2025-10-20
DOMAIN cryptocopedia.com 2024-07-08 2025-05-16
URL https://cryptocopedia.com/explo… 2024-07-08 2024-08-24

Related Reports

« Back