npm Malware, Fake Devs, and Deepfake Videos: These Are A Few of My Favorite DPRK Things

2026-04-07 NKInternet

https://nkinternet.com/2026/04/07/npm-malware-fake-devs-and-deepfake-videos-these-are-a-few-of-my-favorite-dprk-things/

Thumbnail for npm Malware, Fake Devs, and Deepfake Videos: These Are A Few of My Favorite DPRK Things

An investigation into the Mentonex GitHub organization found an active npm backdoor chain, fake developer personas, and facilitator-recruitment activity that the author says maps closely to documented DPRK tradecraft. The malicious chain used logkitx, logger-base, and dev-log-core packages published by the same npm account, with dev-log-core fetching base64-encoded code from Vercel-hosted endpoints and executing it dynamically through new Function(). The payload could access the filesystem, network, and child processes, while infrastructure rotated from ngrok-free.vercel.app to logkit.vercel.app and logkit-tau.vercel.app as the package versions evolved. The report also links the npm infrastructure and persona clusters to patterns seen in North Korea-linked developer-targeting activity, including fake organizations, cloned projects, stock or AI-generated identities, and remote-work facilitator recruitment.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN outlook.com 2018-09-06 2026-04-17
HASH c0c4934fc8b84cd0d699cb5a941a0ec… 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
URL https://www.howtica.com/ 2026-04-07 2026-04-07
URL https://vynyl.com 2026-04-07 2026-04-07
URL https://dev.to/darkbranchcore/w… 2026-04-07 2026-04-07
URL https://www.ideasvoice.com/fr/p… 2026-04-07 2026-04-07
DOMAIN ledhuge.com 2026-04-07 2026-04-07
DOMAIN fluxpy.com 2026-04-07 2026-04-07
DOMAIN fluxypy.com 2026-04-07 2026-04-07
DOMAIN mentonex.com 2026-04-07 2026-04-07
DOMAIN walletdiscover.com 2026-04-07 2026-04-07
DOMAIN enhancv.com 2026-04-07 2026-04-07
DOMAIN blusapiens.com 2026-04-07 2026-04-07
DOMAIN alphacointech1010.io 2026-04-07 2026-04-07
DOMAIN cluster0.x1pgibg.mongodb.net 2026-04-07 2026-04-07
DOMAIN vynyl.com 2026-04-07 2026-04-07
DOMAIN eyecarewell.com 2026-04-07 2026-04-07
DOMAIN fluxmarketx.com 2026-04-07 2026-04-07
DOMAIN arclyntech.com 2026-04-07 2026-04-07
DOMAIN apexautocap.com 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07

Related Reports

« Back