North Korean State Actors Exploit Open Source Supply Chain via Malicious npm Package

2024-07-24 Stacklok

https://stacklok.com/blog/north-korean-state-actors-exploit-open-source-supply-chain-via-malicious-npm-package

Thumbnail for North Korean State Actors Exploit Open Source Supply Chain via Malicious npm Package

Stacklok reports that the npm package next-react-notify, published on 22 July 2024, copied the popular call-bind package and added a preinstall script that executed and deleted a downloader. On Windows systems, the script wrote execu.bat and yui.ps1, fetched an encrypted second stage from 166.88.61[.]72, XOR-decrypted it, renamed it to soss.dat, and ran it through rundll32. The hosting IP had resolved to cryptocopedia[.]com, infrastructure linked in earlier reporting on North Korean npm activity, and the package was unpublished less than four hours after publication. Stacklok assessed with reasonable confidence that the activity continued the same North Korean state-aligned open source supply chain campaign, while avoiding attribution to a specific group.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN cryptocopedia.com 2024-07-08 2025-05-16
HASH 43a28fc5a1ee46da0e5698fed473802… 2024-07-24 2024-07-24
HASH b57b75d015526b862ae469b825c7a18… 2024-07-24 2024-07-24
HASH 9d27159f34d4534afaa3f3e8de51c4d… 2024-07-24 2024-07-24
HASH 337c114002a8b25b1ee47546b637391… 2024-07-24 2024-07-24
IPv4 166.88.61.72 2024-07-24 2024-07-24

Related Reports

« Back