Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors

2024-04-25 • Securonix •

https://www.securonix.com/blog/analysis-of-devpopper-new-attack-campaign-targeting-software-developers-likely-associated-with-north-korean-threat-actors/

Thumbnail for Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors

Securonix tracks DEV#POPPER as an ongoing social engineering campaign likely tied to North Korean threat actors and aimed at software developers. Attackers pose as interviewers, send GitHub-hosted coding tasks, and rely on the target running a malicious NPM package during the fake interview process. The first-stage JavaScript downloads an archive from 147.124.214[.]131:1244, extracts a hidden Python payload, and runs follow-on Python code that contains hard-coded C2 infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 147.124.214.131 2024-04-25 2026-09-21
IPv4 173.211.106.101 2024-04-25 2025-07-26
HASH 33617f0ac01a0f7fa5f64bd8edef737… 2024-04-25 2024-08-26
HASH 45c991529a421104f2edf03d92e01d9… 2024-04-25 2024-05-10
HASH 977a9024962102b02128d391c0543c6… 2024-04-25 2024-04-25
HASH f9ca12321fb91157cce8513e935810d… 2024-04-25 2024-04-25

Related Reports

« Back