North Korean Hackers Target Developers with 338 Malicious Software Packages
## Cybersecurity: North Korean Threat Actors Escalate Contagious Interview Campaign
Cybersecurity: North Korean Threat Actors Escalate Contagious Interview Campaign
North Korean threat actors have intensified their Contagious Interview campaign by deploying 338 malicious npm packages with over 50,000 downloads. This campaign targets cryptocurrency and blockchain developers through advanced social engineering techniques.
The operation signifies a substantial advancement in supply chain attacks, employing over 180 fake personas and numerous command and control endpoints to disseminate sophisticated malware, including BeaverTail and InvisibleFerret backdoors.
The campaign showcases a high degree of technical sophistication, featuring three distinct loader families: HexEval, XORIndex, and encrypted loaders. The social engineering component effectively exploits developers' routine dependency installation processes.
Malicious packages are designed to resemble common dependencies within the Node.js and Express ecosystems. These include typosquatted versions of popular packages like express, dotenv, and body-parser. The campaign also targets Web3 and cryptocurrency development tools, with systematic typosquats of ethers.js and web3.js.
North Korean threat actors have intensified their Contagious Interview campaign by deploying 338 malicious npm packages with over 50,000 downloads.
Infrastructure and Persistence Mechanisms
The campaign's command and control infrastructure utilizes both raw IP addresses on commodity VPS providers and legitimate hosting platforms. Communication is conducted over HTTP/HTTPS and WebSocket protocols.
Installation of the malware establishes long-term access, with the BeaverTail malware and InvisibleFerret backdoor providing persistent access across Windows, macOS, and Linux platforms. This approach enables extended reconnaissance and preparation for cryptocurrency theft.
The operation demonstrates resilience against defensive measures, maintaining weekly upload schedules and adapting quickly to package takedowns by re-uploading variants under new names. As of the latest analysis, 25 malicious packages remain active, highlighting ongoing challenges within the npm ecosystem and broader software supply chain.
Based on reporting by GBHackers.
