216.73.217.22

Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview

· Published 25/10/2024 13:53 · Modified 25/10/2024 15:52

Export JSON

Essential information

Published
25/10/2024 13:53
Modified
25/10/2024 15:52
Tags
2024-10-25 beavertail contagious interview cryptocurrency dprk infostealer invisibleferret namesquatting npm software supply chain
Related entities
1 observables, 1 intrusion sets (apt), 15 techniques (mitre), 2 malware, 2 others

Description

Datadog Security Research discovered three malicious packages: passports-js, bcrypts-js, and blockscan-api, containing malware associated with North Korean threat actors. The packages, downloaded 323 times, targeted job-seekers in the US tech industry through a campaign named . The malware, obfuscated using common techniques, steals wallet and credit card information from browser caches and login keychains on Unix and Windows systems. The attackers used to mimic legitimate packages and exploited the open source . Two different campaign IDs were identified, suggesting potentially new efforts to target Node.js developers. The activity was linked to the campaign through shared infrastructure and tactics.

External references