How North Korea is Compromising Supply Chains

2023-12-12 Checkmarx

https://medium.com/checkmarx-security/how-north-korea-is-compromising-supply-chains-df1532b29a49

Thumbnail for How North Korea is Compromising Supply Chains

Checkmarx describes two North Korea-linked supply-chain tradecraft paths observed in 2023: malicious npm/PyPI-style package-manager poisoning and developer-focused Contagious Interview lures hosted through GitHub. In the npm case, crypto-themed packages used a preinstall hook to drop batch and PowerShell scripts, download a second-stage payload such as npm.mov, decrypt it into a DLL masquerading as a database, execute it with rundll32, and then delete or rename files to hide the install hook. The report also ties job-interview repositories to North Korean social engineering against developers, where victims were pushed to install malicious packages that steal sensitive data and cryptocurrency-wallet material and establish backdoor access. The key operational point is that DPRK actors are abusing developer trust in package managers, GitHub repositories, repository popularity signals, and hiring workflows to compromise software supply chains.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 147.124.212.89 2023-12-12 2025-11-13
HASH 72ebfe69c69d2dd173bb92013ab44d8… 2023-11-21 2025-10-16
HASH 6465f7ddc9cf8ab6714cbbd49e1fd47… 2023-11-21 2024-10-23
IPv4 144.172.79.23 2023-11-21 2024-10-23
IPv4 167.88.168.24 2023-11-21 2024-10-23
IPv4 45.61.169.187 2023-11-21 2024-10-23
IPv4 167.88.168.152 2023-11-21 2024-10-23
IPv4 144.172.74.48 2023-11-21 2024-10-23
IPv4 45.61.160.14 2023-11-21 2024-10-23
IPv4 172.86.123.35 2023-11-21 2024-10-23
HASH a2f8de3c5f5f6ecbf29c15afd43a7c1… 2023-11-21 2024-09-12
HASH 592769457001374fac7a44379282ddf… 2023-11-21 2024-09-12
HASH 7f8bb754f84a06b3e3617dd1138f07a… 2023-11-21 2024-09-12
HASH 61dff5cbad45b4fe0852ac95b96b629… 2023-11-21 2024-09-12
HASH 6b3fce8f2dad7e803418edd8dfc807b… 2023-11-21 2024-09-12
HASH 0ce264819c7af1c485878ce795fd472… 2023-11-21 2024-09-12
HASH 1b21556fc8ecb9f8169ba0482de857b… 2023-11-21 2024-09-12
HASH 104926c2c937b4597ea3493bccb7683… 2023-11-21 2024-09-12
HASH 4c605c6ef280b4ed5657fe97ba5b610… 2023-11-21 2024-09-12
HASH 7b718a46ae4de09ed4f2513df6e989a… 2023-11-21 2024-09-12
HASH 700a582408cbda7ee79723b3969b8d1… 2023-11-21 2024-09-12
HASH 9ae24a1912e4b0bab76ae97484b62ea… 2023-11-21 2024-09-12
HASH 121ca625f582add0527f888bb84b319… 2023-11-21 2024-09-12
HASH 4c465e6c8f43f7d13a1b887ff26d9a3… 2023-11-21 2024-09-12
HASH 92aeea4c32013b935cd8550a082aff1… 2023-11-21 2024-09-12
HASH 9867f99a66e64f6bce0cfca18b12419… 2023-11-21 2024-09-12
HASH 709820850127201a17caab273e01bb3… 2023-11-21 2024-09-12
HASH 75f9f99295f86de85a8a2e4d73ed569… 2023-11-21 2024-09-12
HASH 41a912d72ba9d5db95094be333f79b6… 2023-11-21 2024-09-12
HASH 12c0f44a931b9d0d74a2892565363be… 2023-11-21 2024-09-12
HASH 785f65f1853a08b0e86db5638fbd76e… 2023-11-21 2024-09-12
HASH c5a73896dc628c23a0b6210f5001944… 2023-11-21 2024-09-12
HASH ceb59dbaf58a8de02f9d5e9b497321d… 2023-11-21 2024-09-12
HASH de42155e14a3c9c4d919316d6ba8302… 2023-11-21 2024-09-12
HASH 1f9169492d18bffacebe951a22495d5… 2023-11-21 2024-09-12
HASH da6d9c837c7c2531f0dbb7ce92bfceb… 2023-11-21 2024-09-12
HASH d8f065d264b1112d6ee3cf34979289e… 2023-11-21 2024-09-12
HASH b833f40b2f3439f317cf95980b29bdd… 2023-11-21 2024-09-12
HASH c8c11f9b308ea5983eebd8a41468402… 2023-11-21 2024-09-12
HASH 845d7978682fa19161281a35b62f4c4… 2023-11-21 2024-09-12
HASH 2d8a5b637a95de3b709780898b7c395… 2023-11-21 2024-09-12
HASH 1123fea9d3a52989ec34041f791045c… 2023-11-21 2024-09-12
HASH b5f151f0a4288e148fd10e19c78399f… 2023-11-21 2024-09-12
HASH ff620bd560485c13a58a0de941bd3e5… 2023-11-21 2024-09-12
HASH fc9bb03998a89524ce5a0f859feb458… 2023-11-21 2024-09-12
HASH e2a940c7d19409e960427749519dc02… 2023-11-21 2024-09-12
HASH db6e75987cabdbfc21d0fdcb1cdae98… 2023-11-21 2024-09-12
HASH 2618a067e976f35f65aee95fecc9a8f… 2023-11-21 2024-09-12
HASH 40645f9052e03fed3a33a7e0f58bc2c… 2023-11-21 2024-09-12
HASH 09a508e99b905330a3ebb7682c0dd57… 2023-11-21 2024-09-12
IPv4 172.86.98.143 2023-12-12 2024-09-04
DOMAIN blocktestingto.com 2023-11-21 2024-09-04
IPv4 91.206.178.125 2023-11-04 2024-07-05
IPv4 103.179.142.171 2023-11-04 2024-01-19
HASH 2d300410a3edb77b5f1f0ff2aa2d378… 2023-11-21 2023-12-12
HASH ab198c5a79cd9dedb271bd8a56ab568… 2023-11-21 2023-12-12
HASH 276863ee7b250419411b39c8539c318… 2023-11-21 2023-12-12
HASH 1c905fa3a108f4c9bc0578882ce7af9… 2023-11-21 2023-12-12
HASH 35434e903bc3be183fa07b9e99d49c0… 2023-11-21 2023-12-12
HASH 305de20b24e2662d47f06f16a5998ef… 2023-11-21 2023-12-12
HASH 617c62da1c228ec6d264f89e375e9a5… 2023-11-21 2023-12-12
HASH 03185038cad7126663550d2290a14a1… 2023-11-21 2023-12-12
HASH 4f50051ae3cb57f10506c6d69d7c973… 2023-11-21 2023-12-12
HASH 39e7f94684129efce4d070d89e27508… 2023-11-21 2023-12-12
HASH 444f56157dfcf9fc2347911a00fe9f3… 2023-11-21 2023-12-12
HASH c547b80e1026d562ac851be007792ae… 2023-11-21 2023-12-12

Related Reports

« Back