Popular Development Framework Neutralinojs Compromised In DPRK Attack
2026-03-06 • OSM •
OpenSourceMalware reports that DPRK threat actors compromised four Neutralinojs GitHub organization repositories in a 132-second automated burst on March 2, 2026. The attacker used the alphagamer7 account to force-push backdated malicious commits, spoof maintainer or github-actions[bot] identities, and hide obfuscated JavaScript after whitespace in files such as spec/runner.js, src/constants.js, babel.config.js, and .env-backed configuration. The activity is tied by the source to a broader DPRK campaign against open-source maintainers, with the final payload described as the latest BeaverTail malware associated with Contagious Interview operations. The compromise is significant because Neutralinojs has thousands of users, and poisoned upstream repositories can spread infostealer and backdoor code to developers and dependent projects before maintainers notice the history manipulation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d62abe0288901ba91fe7782094342d4… | 2026-03-06 | 2026-03-06 |
| HASH | 720c0e39c02184952d24fb5dabe19d8… | 2026-03-06 | 2026-03-06 |
| HASH | d4e269df0f50998c7ebf2bf56945d3d… | 2026-03-06 | 2026-03-06 |
| HASH | 11e87f7f27b3cf1a51e0b4b3903decd… | 2026-03-06 | 2026-03-06 |
| HASH | 904afe0337fbbd79def403b3204f75b… | 2026-03-06 | 2026-03-06 |
| HASH | a507b74b6b1e25444c586bc67ae0244… | 2026-03-06 | 2026-03-06 |
| HASH | 90665b4bed716c05e75ec181ddf7af9… | 2026-03-06 | 2026-03-06 |
| HASH | 6c19a3106b6f6f2725c530e37bfac7f… | 2026-03-06 | 2026-03-06 |
| URL | https://data-kappa.vercel.app/ | 2026-03-06 | 2026-03-06 |
| URL | https://auth-rho-dun.vercel.app… | 2026-03-06 | 2026-03-06 |