Tenacious Pungsan
2024-10-24 • Datadog • Tenacious Pungsan: A DPRK threat actor linked to …
Datadog Security Research disclosed in October 2024 a malicious npm package cluster it designates Tenacious Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. In September 2024, Datadog identified three npm packages, backdoored copies of popular open-source authentication and blockchain-API libraries, that together had a few hundred downloads and contained an obfuscated variant of BeaverTail, a JavaScript infostealer and downloader first identified by Palo Alto Networks Unit 42 in late 2023. BeaverTail targets cryptocurrency wallets and stored browser and payment-card data, and downloads a second-stage Python backdoor known as InvisibleFerret. Based on shared command-and-control infrastructure, a reused server directory structure, and consistent malware behavior, Datadog attributed these packages with high confidence to the Contagious Interview campaign, an ongoing DPRK-linked operation that lures technology-industry job seekers into fake interviews where the malware is delivered as a fabricated interview task, indicating this npm supply-chain activity forms part of that broader campaign targeting individual software developers.
-
28
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster