I was likely targeted by DPRK in a sophisticated developer malware campaign

2026-05-25 Denv

https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-a-sophisticated-developer-malware-campaign/

Thumbnail for I was likely targeted by DPRK in a sophisticated developer malware campaign

A fake Pulsynk recruiting email targeted a smart-contract security developer with instructions to clone a GitLab repository and open it in VS Code or Cursor. The repository abused a `.vscode/tasks.json` folder-open task to install a malicious VS Code extension masquerading as Google Update Support, which then dropped native Go implants for macOS and Linux. The malware sought cryptocurrency wallets, browser credentials and sessions, SSH keys, `.env` files, package-manager tokens, and credential-store data, with a macOS fake System Security Update prompt used to harvest login credentials. Its encrypted WebSocket C2 used `23.137.105.75:5173` and upload paths disguised as company-wallet endpoints, while strings and environment variables overlapped with the public Overlord RAT project. The author notes overlap with DPRK-linked Contagious Interview developer targeting but treats attribution as tradecraft similarity rather than proof of operator identity.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN hr.pulsynk.org 2026-05-25 2026-06-08
EMAIL [email protected] 2026-05-25 2026-05-25
EMAIL [email protected] 2026-05-25 2026-05-25
URL https://gitlab.com/pulsynk-org/… 2026-05-25 2026-05-25
DOMAIN pulsynk.org 2026-05-25 2026-05-25
HASH 04350366c28dea9b224d62ce18bd6bb7 2026-05-25 2026-05-25
IPv4 23.137.105.75 2026-05-25 2026-05-25

Related Actors

Related Reports

« Back