Exposed DPRK reference malware and logs
2026-02-16 • Kmsec •
KMSEC documents two accidental operational-security exposures linked to FAMOUS CHOLLIMA npm activity. Several malicious packages published between July and September 2025 included an `ordinary.txt` JavaScript source file that appears to have been a reference sample before modification and obfuscation, with commented code and a local payload server on port 4444. A separate `err.log` in the `some-promise` package exposed a Windows path, the operator username `dvant`, and evidence that the actor was modifying the legitimate `any-promise` package in place before publishing a malicious version. These artifacts are not directly defensive indicators, but they provide useful context on DPRK-linked npm malware development practices and operator mistakes.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | dcde20e9104c953246a379a54c2292e… | 2026-02-16 | 2026-02-16 |
| HASH | 02fa6ff6ea920eb38ab040a2f2debef… | 2026-02-16 | 2026-02-16 |
| HASH | c5e75f4641a5add4516c6785c345416… | 2026-02-16 | 2026-02-16 |