Novel DPRK stager using Pastebin and text steganography

2026-02-26 Kmsec

https://kmsec.uk/blog/dprk-text-steganography/

Thumbnail for Novel DPRK stager using Pastebin and text steganography

FAMOUS CHOLLIMA published seventeen npm packages on 25-26 February 2026 that used Pastebin and custom text steganography as a dead-drop resolver. Each package ran an install script that loaded an obfuscated vendor/scrypt-js/version.js payload, fetched Pastebin text, decoded hidden characters into Vercel C2 hostnames, and then attempted those hosts as fallbacks. The active Vercel deployment ext-checkdin[.]vercel[.]app returned OS-specific payloads from /api/l, /api/m, and /api/w that executed follow-on shell commands on Linux, macOS, and Windows. The technique shows rapid experimentation in DPRK-linked npm staging while giving defenders concrete package names, Pastebin references, Vercel domains, paths, and payload hashes for hunting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH da1775d0fbe99fbc35b6f0b4a3a3cb8… 2026-02-26 2026-02-27
HASH bce0da6547ae74f97e2bb61672a3e15… 2026-02-26 2026-02-26
HASH e361d2859ba2eb2540bf6fb12db0b98… 2026-02-26 2026-02-26
HASH 869c327b8dc757fa126cd281bc4a14d… 2026-02-26 2026-02-26
URL https://pastebin.com/CJ5PrtNk 2026-02-26 2026-02-26
URL https://pastebin.com/0ec7i68M 2026-02-26 2026-02-26
URL https://pastebin.com/DjDCxcsT 2026-02-26 2026-02-26

Related Actors

Related Reports

« Back