Stressed Pungsan
2024-08-01 • Datadog • Stressed Pungsan: DPRK-aligned threat actor lever…
Datadog Security Research disclosed in August 2024 a malicious npm package cluster it internally designates Stressed Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. On July 7, 2024, an npm user published two malicious packages that copied a popular open-source Node.js configuration library and added a pre-install script which downloaded and executed, via a living-off-the-land binary, a malicious DLL retrieved from an attacker-controlled server. Datadog assessed that the tactics, techniques, procedures, and command-and-control infrastructure used in this campaign closely align with activity that Microsoft tracks as the North Korean actor Moonstone Sleet. The malicious packages were removed from the npm registry only hours after publication, a pattern Datadog noted this actor uses to publish quickly and evade detection, and the publishing account had no other prior packages. The campaign reflects continued DPRK-aligned abuse of open-source software supply chains, specifically npm, to gain initial access into developer and cloud environments.
-
61
Related Actors
-
691
Related Reports
Related Actors
Related Reports in This Cluster
Top Authors
View Stressed Pungsan reports only