Popular Development Framework Neutralinojs Compromised In DPRK Attack

2026-03-06 OSM

https://opensourcemalware.com/blog/neutralinojs-compromise

Thumbnail for Popular Development Framework Neutralinojs Compromised In DPRK Attack

OpenSourceMalware reports that DPRK threat actors compromised four Neutralinojs GitHub organization repositories in a 132-second automated burst on March 2, 2026. The attacker used the alphagamer7 account to force-push backdated malicious commits, spoof maintainer or github-actions[bot] identities, and hide obfuscated JavaScript after whitespace in files such as spec/runner.js, src/constants.js, babel.config.js, and .env-backed configuration. The activity is tied by the source to a broader DPRK campaign against open-source maintainers, with the final payload described as the latest BeaverTail malware associated with Contagious Interview operations. The compromise is significant because Neutralinojs has thousands of users, and poisoned upstream repositories can spread infostealer and backdoor code to developers and dependent projects before maintainers notice the history manipulation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d62abe0288901ba91fe7782094342d4… 2026-03-06 2026-03-06
HASH 720c0e39c02184952d24fb5dabe19d8… 2026-03-06 2026-03-06
HASH d4e269df0f50998c7ebf2bf56945d3d… 2026-03-06 2026-03-06
HASH 11e87f7f27b3cf1a51e0b4b3903decd… 2026-03-06 2026-03-06
HASH 904afe0337fbbd79def403b3204f75b… 2026-03-06 2026-03-06
HASH a507b74b6b1e25444c586bc67ae0244… 2026-03-06 2026-03-06
HASH 90665b4bed716c05e75ec181ddf7af9… 2026-03-06 2026-03-06
HASH 6c19a3106b6f6f2725c530e37bfac7f… 2026-03-06 2026-03-06
URL https://data-kappa.vercel.app/ 2026-03-06 2026-03-06
URL https://auth-rho-dun.vercel.app… 2026-03-06 2026-03-06

Related Reports

« Back