Exposed DPRK reference malware and logs

2026-02-16 Kmsec

https://kmsec.uk/blog/dprk-opsec-2/

Thumbnail for Exposed DPRK reference malware and logs

KMSEC documents two accidental operational-security exposures linked to FAMOUS CHOLLIMA npm activity. Several malicious packages published between July and September 2025 included an `ordinary.txt` JavaScript source file that appears to have been a reference sample before modification and obfuscation, with commented code and a local payload server on port 4444. A separate `err.log` in the `some-promise` package exposed a Windows path, the operator username `dvant`, and evidence that the actor was modifying the legitimate `any-promise` package in place before publishing a malicious version. These artifacts are not directly defensive indicators, but they provide useful context on DPRK-linked npm malware development practices and operator mistakes.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dcde20e9104c953246a379a54c2292e… 2026-02-16 2026-02-16
HASH 02fa6ff6ea920eb38ab040a2f2debef… 2026-02-16 2026-02-16
HASH c5e75f4641a5add4516c6785c345416… 2026-02-16 2026-02-16

Related Actors

Related Reports

« Back