An attacker, disguised as a job seeker, distributing malware on GitHub
2025-06-03 • ENKI •
ENKI analyzed GitHub repositories where an actor posing as a full-stack and blockchain developer hid malicious scripts inside apparently legitimate projects. In the Ly_AutoPayBot repository, malicious code was concealed far below the visible logger.ts content and executed whenever the module was imported, downloading a disguised DLL from Catbox and launching it through rundll32. The DLL backdoor created multiple threads, used IOCP-based HTTP POST communication with its C&C server, generated an infected-host identifier from the volume GUID path, and protected C&C data and internal strings with Base64 and MT19937-based routines. The excerpt explicitly notes that North Korean IT workers have used fake LinkedIn and GitHub developer profiles for revenue and information theft, but it does not claim the analyzed GitHub actor is North Korean or Lazarus-linked.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8b6d6807213c21c84192cc697d96396… | 2025-06-03 | 2025-06-03 |
| HASH | 5527f0acb4755e4402434f84c0aac60… | 2025-06-03 | 2025-06-03 |
| HASH | 13412b54e3e8f30d3179e54cc653dc6… | 2025-06-03 | 2025-06-03 |
| HASH | 52046ad374041f0cabc47e897e10de8… | 2025-06-03 | 2025-06-03 |
| HASH | 7790c55c5dded39c0a6a0eabf05665c… | 2025-06-03 | 2025-06-03 |
| HASH | 6ac3bd5e67f5ba1f8effbb53d25078e… | 2025-06-03 | 2025-06-03 |
| URL | https://files.catbox.moe/mur3el… | 2025-06-03 | 2025-06-03 |
| URL | https://app.mercuryswap.io | 2025-06-03 | 2025-06-03 |
| URL | https://files.catbox.moe/zxmneq… | 2025-06-03 | 2025-06-03 |
| URL | https://www.dropbox.com/scl/fi/… | 2025-06-03 | 2025-06-03 |
| DOMAIN | app.mercuryswap.io | 2025-06-03 | 2025-06-03 |
| IPv4 | 166.88.117.246 | 2025-06-03 | 2025-06-03 |
| IPv4 | 166.88.90.143 | 2025-06-03 | 2025-06-03 |