A malicious npm package hidden three dependencies deep: the ulid-xyz delivery chain

2026-09-01 Safe Dep

https://safedep.io/ulid-xyz-transitive-dependency-delivery-chain

Thumbnail for A malicious npm package hidden three dependencies deep: the ulid-xyz delivery chain

SafeDep uncovered an npm dependency chain in which `ioredis-xyz` silently resolved `redis-type-xyz` and then the malicious `ulid-xyz` package, whose postinstall hook launched a cross-platform remote access trojan. The implant persisted as MicrosoftSystem64 and contacted Hetzner-hosted command servers over port 8010, allowing operators to inspect hosts and deploy additional binaries. SafeDep linked the operation to the DPRK-associated FAMOUS CHOLLIMA cluster through shared implant and persistence characteristics, matching infrastructure patterns, and direct overlap with the previously identified `whisdev` persona. No second-stage payload was recovered, so the report does not establish what was deployed to individual victims.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2026-09-01 2026-09-01
EMAIL [email protected] 2026-09-01 2026-09-01
URL http://95.216.232.162:8010 2026-09-01 2026-09-01
URL http://65.21.30.171:8010 2026-09-01 2026-09-01
HASH aa01a83c7a420c22a719b02ec327451… 2026-09-01 2026-09-01
HASH 3a9089e9db3650dd6d1584fae709022… 2026-09-01 2026-09-01
HASH a3c28435295fed4babdeefedcefdd0e… 2026-09-01 2026-09-01
IPv4 95.216.232.162 2026-09-01 2026-09-01
IPv4 65.21.30.171 2026-09-01 2026-09-01

Related Actors

Related Reports

« Back