Nation-State Threat Actors Renew Publications to npm
2024-04-24 • Phylum •
Phylum linked new npm publications on 23 April 2024 to a previously reported North Korea-attributed campaign against open-source package ecosystems. The packages react-dom-production-script and hardhat-daemon used a preinstall hook to run deference.js as soon as a developer installed the package. That file was a trojanized and obfuscated version of code from the legitimate node-config package, giving the attackers arbitrary code execution during installation. The activity shows the campaign continuing with small changes in packaging and obfuscation rather than abandoning the npm delivery route.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | matrixane.com | 2024-04-24 | 2024-05-28 |
| URL | https://matrixane.com/download/… | 2024-04-24 | 2024-04-24 |
Related Reports
2024-05-28 •
50% Match
#PuTTY
#NPM
#ITWorker
#MoonstoneSleet
#FakePenny
#Storm-1789
#Storm-1877
#DeTankWar
#DeFiTankLand
Shares tag: NPM • Shares 1 IOC
Shares tag: NPM • Same author: Phylum
Shares tag: NPM • Published within a month
Shares tag: macOS • Published within a month
2024-04-25 •
40% Match
Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors
Securonix
Shares tag: NPM • Published within a week
2024-04-11 •
40% Match
Return of the mac(OS): Transparency, Consent, and Control (TCC) Database Manipulation
Interpres Security
Shares tag: macOS • Published within a month