North Korean State Actors Exploit Open Source Supply Chain via Malicious npm Package
2024-07-24 • Stacklok •
Stacklok reports that the npm package next-react-notify, published on 22 July 2024, copied the popular call-bind package and added a preinstall script that executed and deleted a downloader. On Windows systems, the script wrote execu.bat and yui.ps1, fetched an encrypted second stage from 166.88.61[.]72, XOR-decrypted it, renamed it to soss.dat, and ran it through rundll32. The hosting IP had resolved to cryptocopedia[.]com, infrastructure linked in earlier reporting on North Korean npm activity, and the package was unpublished less than four hours after publication. Stacklok assessed with reasonable confidence that the activity continued the same North Korean state-aligned open source supply chain campaign, while avoiding attribution to a specific group.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | cryptocopedia.com | 2024-07-08 | 2025-05-16 |
| HASH | 43a28fc5a1ee46da0e5698fed473802… | 2024-07-24 | 2024-07-24 |
| HASH | b57b75d015526b862ae469b825c7a18… | 2024-07-24 | 2024-07-24 |
| HASH | 9d27159f34d4534afaa3f3e8de51c4d… | 2024-07-24 | 2024-07-24 |
| HASH | 337c114002a8b25b1ee47546b637391… | 2024-07-24 | 2024-07-24 |
| IPv4 | 166.88.61.72 | 2024-07-24 | 2024-07-24 |