Novel DPRK stager using Pastebin and text steganography
2026-02-26 • Kmsec •
FAMOUS CHOLLIMA published seventeen npm packages on 25-26 February 2026 that used Pastebin and custom text steganography as a dead-drop resolver. Each package ran an install script that loaded an obfuscated vendor/scrypt-js/version.js payload, fetched Pastebin text, decoded hidden characters into Vercel C2 hostnames, and then attempted those hosts as fallbacks. The active Vercel deployment ext-checkdin[.]vercel[.]app returned OS-specific payloads from /api/l, /api/m, and /api/w that executed follow-on shell commands on Linux, macOS, and Windows. The technique shows rapid experimentation in DPRK-linked npm staging while giving defenders concrete package names, Pastebin references, Vercel domains, paths, and payload hashes for hunting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | da1775d0fbe99fbc35b6f0b4a3a3cb8… | 2026-02-26 | 2026-02-27 |
| HASH | bce0da6547ae74f97e2bb61672a3e15… | 2026-02-26 | 2026-02-26 |
| HASH | e361d2859ba2eb2540bf6fb12db0b98… | 2026-02-26 | 2026-02-26 |
| HASH | 869c327b8dc757fa126cd281bc4a14d… | 2026-02-26 | 2026-02-26 |
| URL | https://pastebin.com/CJ5PrtNk | 2026-02-26 | 2026-02-26 |
| URL | https://pastebin.com/0ec7i68M | 2026-02-26 | 2026-02-26 |
| URL | https://pastebin.com/DjDCxcsT | 2026-02-26 | 2026-02-26 |