npm Malware, Fake Devs, and Deepfake Videos: These Are A Few of My Favorite DPRK Things
2026-04-07 • NKInternet •
An investigation into the Mentonex GitHub organization found an active npm backdoor chain, fake developer personas, and facilitator-recruitment activity that the author says maps closely to documented DPRK tradecraft. The malicious chain used logkitx, logger-base, and dev-log-core packages published by the same npm account, with dev-log-core fetching base64-encoded code from Vercel-hosted endpoints and executing it dynamically through new Function(). The payload could access the filesystem, network, and child processes, while infrastructure rotated from ngrok-free.vercel.app to logkit.vercel.app and logkit-tau.vercel.app as the package versions evolved. The report also links the npm infrastructure and persona clusters to patterns seen in North Korea-linked developer-targeting activity, including fake organizations, cloned projects, stock or AI-generated identities, and remote-work facilitator recruitment.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | outlook.com | 2018-09-06 | 2026-04-17 |
| HASH | c0c4934fc8b84cd0d699cb5a941a0ec… | 2026-04-07 | 2026-04-07 |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| URL | https://www.howtica.com/ | 2026-04-07 | 2026-04-07 |
| URL | https://vynyl.com | 2026-04-07 | 2026-04-07 |
| URL | https://dev.to/darkbranchcore/w… | 2026-04-07 | 2026-04-07 |
| URL | https://www.ideasvoice.com/fr/p… | 2026-04-07 | 2026-04-07 |
| DOMAIN | ledhuge.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | fluxpy.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | fluxypy.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | mentonex.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | walletdiscover.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | enhancv.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | blusapiens.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | alphacointech1010.io | 2026-04-07 | 2026-04-07 |
| DOMAIN | cluster0.x1pgibg.mongodb.net | 2026-04-07 | 2026-04-07 |
| DOMAIN | vynyl.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | eyecarewell.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | fluxmarketx.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | arclyntech.com | 2026-04-07 | 2026-04-07 |
| DOMAIN | apexautocap.com | 2026-04-07 | 2026-04-07 |
| [email protected] | 2026-04-07 | 2026-04-07 |