Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators

2026-03-17 Kmsec

https://kmsec.uk/blog/contagious-trader/

Thumbnail for Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators

kmsec.uk reports that Contagious Trader targets cryptocurrency users through malicious GitHub trading bot repositories and npm packages themed around Polymarket, Kalshi, Solana, Raydium, copy trading, and related market activity. The author attributes the campaign to North Korea/Lazarus operations with high confidence, while avoiding assignment to a specific subgroup, based on overlaps with Contagious Interview tradecraft, GitHub and npm abuse, Vercel infrastructure, Base64-encoded endpoints, temporary email use, Astrill VPN publish sources, and package masquerading. Infection paths include direct HTTP/S exfiltration, MongoDB exfiltration, malicious npm dependencies, transitive dependency chains, file theft, and Linux SSH backdoor behavior through authorized_keys modification and ufw changes. The report lists repositories, npm packages, operator publish evidence, domains, IP addresses, Vercel endpoints, and MongoDB hosts that defenders can use to hunt poisoned trading bot projects and dependency-chain compromise.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN api.fivefingerz.dev 2026-03-17 2026-04-29
DOMAIN polymarket-clob.com 2026-03-17 2026-04-29
DOMAIN clob-polymarket.com 2026-03-17 2026-04-29
IPv4 45.8.22.144 2026-03-17 2026-04-29
DOMAIN outlook.com 2018-09-06 2026-04-17
DOMAIN googlemail.com 2025-10-10 2026-04-07
EMAIL [email protected] 2026-03-17 2026-03-17
EMAIL [email protected] 2026-03-17 2026-03-17
URL https://nodejs-be-production.up… 2026-03-17 2026-03-17
URL https://cloudflareinsights.verc… 2026-03-17 2026-03-17
URL https://eslint-helper.vercel.ap… 2026-03-17 2026-03-17
URL https://chalk-logger.vercel.app/ 2026-03-17 2026-03-17
DOMAIN julius.tan.biz 2026-03-17 2026-03-17
DOMAIN api.bpkythuat.com 2026-03-17 2026-03-17
DOMAIN aster.iejv3bg.mongodb.net 2026-03-17 2026-03-17
DOMAIN cluster0.1ufrx5i.mongodb.net 2026-03-17 2026-03-17
DOMAIN emailnator.com 2026-03-17 2026-03-17
IPv4 87.120.102.178 2026-03-17 2026-03-17
IPv4 154.38.188.168 2026-03-17 2026-03-17
IPv4 23.137.105.114 2026-03-17 2026-03-17
IPv4 39.144.60.174 2026-03-17 2026-03-17
IPv4 65.109.25.6 2026-03-17 2026-03-17
IPv4 89.187.161.180 2026-01-21 2026-03-17
IPv4 66.150.196.58 2026-01-21 2026-03-17
IPv4 192.161.60.132 2026-01-21 2026-03-17
DOMAIN api.ipify.org 2019-12-11 2026-03-17

Related Actors

Related Reports

« Back