216.73.217.22

North Korea Still Attacking Developers via npm

· Published 30/09/2024 10:02 · Modified 30/09/2024 10:18

Export JSON

Essential information

Published
30/09/2024 10:02
Modified
30/09/2024 10:18
Tags
2024-09-30 contagious interview cryptocurrency exfiltration javascript malware moonstone sleet multi-stage attack npm obfuscation persistence python
Related entities
12 observables, 1 intrusion sets (apt), 11 techniques (mitre), 2 malware, 1 others

Description

Recent weeks have seen a resurgence of North Korean-aligned groups targeting developers through packages. The campaign, which began on August 12, 2024, involves multiple groups using various publication patterns and attack types. The malicious packages contain obfuscated that downloads additional components, including scripts and interpreters, to exfiltrate sensitive data from wallets and establish . Some packages use different approaches, such as directly evaluating from remote endpoints or executing batch and PowerShell scripts to deploy and conceal . This coordinated effort exploits the trust in the ecosystem to compromise developers, infiltrate companies, and steal or other valuable assets.

External references