Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators
2026-03-17 • Kmsec •
kmsec.uk reports that Contagious Trader targets cryptocurrency users through malicious GitHub trading bot repositories and npm packages themed around Polymarket, Kalshi, Solana, Raydium, copy trading, and related market activity. The author attributes the campaign to North Korea/Lazarus operations with high confidence, while avoiding assignment to a specific subgroup, based on overlaps with Contagious Interview tradecraft, GitHub and npm abuse, Vercel infrastructure, Base64-encoded endpoints, temporary email use, Astrill VPN publish sources, and package masquerading. Infection paths include direct HTTP/S exfiltration, MongoDB exfiltration, malicious npm dependencies, transitive dependency chains, file theft, and Linux SSH backdoor behavior through authorized_keys modification and ufw changes. The report lists repositories, npm packages, operator publish evidence, domains, IP addresses, Vercel endpoints, and MongoDB hosts that defenders can use to hunt poisoned trading bot projects and dependency-chain compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | api.fivefingerz.dev | 2026-03-17 | 2026-04-29 |
| DOMAIN | polymarket-clob.com | 2026-03-17 | 2026-04-29 |
| DOMAIN | clob-polymarket.com | 2026-03-17 | 2026-04-29 |
| IPv4 | 45.8.22.144 | 2026-03-17 | 2026-04-29 |
| DOMAIN | outlook.com | 2018-09-06 | 2026-04-17 |
| DOMAIN | googlemail.com | 2025-10-10 | 2026-04-07 |
| [email protected] | 2026-03-17 | 2026-03-17 | |
| [email protected] | 2026-03-17 | 2026-03-17 | |
| URL | https://nodejs-be-production.up… | 2026-03-17 | 2026-03-17 |
| URL | https://cloudflareinsights.verc… | 2026-03-17 | 2026-03-17 |
| URL | https://eslint-helper.vercel.ap… | 2026-03-17 | 2026-03-17 |
| URL | https://chalk-logger.vercel.app/ | 2026-03-17 | 2026-03-17 |
| DOMAIN | julius.tan.biz | 2026-03-17 | 2026-03-17 |
| DOMAIN | api.bpkythuat.com | 2026-03-17 | 2026-03-17 |
| DOMAIN | aster.iejv3bg.mongodb.net | 2026-03-17 | 2026-03-17 |
| DOMAIN | cluster0.1ufrx5i.mongodb.net | 2026-03-17 | 2026-03-17 |
| DOMAIN | emailnator.com | 2026-03-17 | 2026-03-17 |
| IPv4 | 87.120.102.178 | 2026-03-17 | 2026-03-17 |
| IPv4 | 154.38.188.168 | 2026-03-17 | 2026-03-17 |
| IPv4 | 23.137.105.114 | 2026-03-17 | 2026-03-17 |
| IPv4 | 39.144.60.174 | 2026-03-17 | 2026-03-17 |
| IPv4 | 65.109.25.6 | 2026-03-17 | 2026-03-17 |
| IPv4 | 89.187.161.180 | 2026-01-21 | 2026-03-17 |
| IPv4 | 66.150.196.58 | 2026-01-21 | 2026-03-17 |
| IPv4 | 192.161.60.132 | 2026-01-21 | 2026-03-17 |
| DOMAIN | api.ipify.org | 2019-12-11 | 2026-03-17 |