DPRK Contagious Interview: NPMJS chalk-ultra and vitest-cli

2026-06-23 • Ossprey •

https://www.ossprey.com/blog/dprk-contagious-interview-npmjs-chalk-ultra-and-vitest-cli

Thumbnail for DPRK Contagious Interview: NPMJS chalk-ultra and vitest-cli

The malicious npm packages `chalk-ultra` and `vitest-cli` execute a hidden downloader that steals developer credentials, source code, browser data, and cryptocurrency-wallet information. The payload can replace Chrome's MetaMask extension with a persistent trojanized version that captures the victim's wallet password. Ossprey links the packages to the DPRK Contagious Interview campaign through shared developer targeting, `jsonkeeper.com` payload delivery, detached execution, and the MetaMask-replacement technique, while noting that attribution of these specific packages remains unconfirmed. Affected systems should be treated as compromised and their credentials and wallet seed phrases rotated.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN jsonkeeper.com 2025-11-13 2026-09-21
IPv4 138.201.140.23 2026-06-23 2026-07-02

Related Actors

Related Reports

« Back