First instance of PylangGhost RAT observed on npm

2026-03-13 Kmsec

https://kmsec.uk/blog/pylangghost-npm/

Thumbnail for First instance of PylangGhost RAT observed on npm

KMSEC found two npm packages published by jaime9008 distributing an obfuscated loader for PylangGhost, a RAT the excerpt says Cisco Talos attributed to FAMOUS CHOLLIMA. Malicious versions of react-refresh-update and @jaime9008/math-service used runtime.js, babel.js, and lib.js as infection points, with a decode, XOR-decrypt, and eval loader chain. The decrypted JavaScript selected payload URLs by operating system, downloaded Windows, macOS, or Linux components from malicanbur[.]pro, and executed scripts or archives to launch the follow-on malware. The report identifies malicanbur[.]pro, 173.211.46[.]22:8080, package versions, a sample hash, and Chrome extension enumeration behavior, showing DPRK-linked tooling moving into npm package distribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 323ba89ec7410656629f8a1e7890d30… 2026-03-13 2026-03-13
HASH 0be2375362227f846c56c4de2db4d31… 2026-03-13 2026-03-13
URL https://malicanbur.pro 2026-03-13 2026-03-13
URL https://malicanbur.pro/winnmrep… 2026-03-13 2026-03-13
DOMAIN malicanbur.pro 2026-03-13 2026-03-13
IPv4 173.211.46.22 2026-03-13 2026-03-13

Related Actors

Related Reports

« Back