Tenacious Pungsan

2024-10-24 • DatadogTenacious Pungsan: A DPRK threat actor linked to …

Datadog Security Research disclosed in October 2024 a malicious npm package cluster it designates Tenacious Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. In September 2024, Datadog identified three npm packages, backdoored copies of popular open-source authentication and blockchain-API libraries, that together had a few hundred downloads and contained an obfuscated variant of BeaverTail, a JavaScript infostealer and downloader first identified by Palo Alto Networks Unit 42 in late 2023. BeaverTail targets cryptocurrency wallets and stored browser and payment-card data, and downloads a second-stage Python backdoor known as InvisibleFerret. Based on shared command-and-control infrastructure, a reused server directory structure, and consistent malware behavior, Datadog attributed these packages with high confidence to the Contagious Interview campaign, an ongoing DPRK-linked operation that lures technology-industry job seekers into fake interviews where the malware is delivered as a fabricated interview task, indicating this npm supply-chain activity forms part of that broader campaign targeting individual software developers.

Related Actors

Related Reports in This Cluster

Top Authors

View Tenacious Pungsan reports only

View Tenacious Pungsan reports only