North Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign
Another set of 67 malicious packages has been seen being published to the npm registry by North Korean threat actors associated with the Contagious Interview campaign, highlighting further efforts to contaminate the open-source ecosystem through software supply chain attacks.
According to Socket, the packages, which include an as-yet-unknown variant of a malware loader called XORIndex, have had over 17,000 downloads. The action is a continuation of an attack wave observed last month that used another loader known as HexEval to distribute packages at a rate of 35 rpm.
According to Socket researcher Kirill Boychenko, "The Contagious Interview operation still operates in a whack-a-mole fashion, with defenders identifying and reporting malicious packages and North Korean threat actors p...

