DPRK Contagious Interview: NPMJS chalk-ultra and vitest-cli

2026-06-23 Ossprey

https://www.ossprey.com/blog/dprk-contagious-interview-npmjs-chalk-ultra-and-vitest-cli

Thumbnail for DPRK Contagious Interview: NPMJS chalk-ultra and vitest-cli

The malicious npm packages `chalk-ultra` and `vitest-cli` execute a hidden downloader that steals developer credentials, source code, browser data, and cryptocurrency-wallet information. The payload can replace Chrome's MetaMask extension with a persistent trojanized version that captures the victim's wallet password. Ossprey links the packages to the DPRK Contagious Interview campaign through shared developer targeting, `jsonkeeper.com` payload delivery, detached execution, and the MetaMask-replacement technique, while noting that attribution of these specific packages remains unconfirmed. Affected systems should be treated as compromised and their credentials and wallet seed phrases rotated.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 138.201.140.23 2026-06-23 2026-07-02

Related Actors

Related Reports

« Back