A malicious npm package hidden three dependencies deep: the ulid-xyz delivery chain
2026-09-01 • Safe Dep •
https://safedep.io/ulid-xyz-transitive-dependency-delivery-chain
SafeDep uncovered an npm dependency chain in which `ioredis-xyz` silently resolved `redis-type-xyz` and then the malicious `ulid-xyz` package, whose postinstall hook launched a cross-platform remote access trojan. The implant persisted as MicrosoftSystem64 and contacted Hetzner-hosted command servers over port 8010, allowing operators to inspect hosts and deploy additional binaries. SafeDep linked the operation to the DPRK-associated FAMOUS CHOLLIMA cluster through shared implant and persistence characteristics, matching infrastructure patterns, and direct overlap with the previously identified `whisdev` persona. No second-stage payload was recovered, so the report does not establish what was deployed to individual victims.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2026-09-01 | 2026-09-01 | |
| [email protected] | 2026-09-01 | 2026-09-01 | |
| URL | http://95.216.232.162:8010 | 2026-09-01 | 2026-09-01 |
| URL | http://65.21.30.171:8010 | 2026-09-01 | 2026-09-01 |
| HASH | aa01a83c7a420c22a719b02ec327451… | 2026-09-01 | 2026-09-01 |
| HASH | 3a9089e9db3650dd6d1584fae709022… | 2026-09-01 | 2026-09-01 |
| HASH | a3c28435295fed4babdeefedcefdd0e… | 2026-09-01 | 2026-09-01 |
| IPv4 | 95.216.232.162 | 2026-09-01 | 2026-09-01 |
| IPv4 | 65.21.30.171 | 2026-09-01 | 2026-09-01 |