North Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign

Another set of 67 malicious packages has been seen being published to the npm registry by North Korean threat actors associated with the Contagious Interview campaign, highlighting further efforts to contaminate the open-source ecosystem through software supply chain attacks.

According to Socket, the packages, which include an as-yet-unknown variant of a malware loader called XORIndex, have had over 17,000 downloads. The action is a continuation of an attack wave observed last month that used another loader known as HexEval to distribute packages at a rate of 35 rpm.

According to Socket researcher Kirill Boychenko, “The Contagious Interview operation still operates in a whack-a-mole fashion, with defenders identifying and reporting malicious packages and North Korean threat actors promptly uploading new variants using the same, similar, or slightly evolved playbooks.”

A long-running effort known as “Contagious Interview” aims to get engineers to download and complete an open-source project read more about North Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *