DPRK Contagious Interview: NPMJS chalk-ultra and vitest-cli
2026-06-23 • Ossprey •
https://www.ossprey.com/blog/dprk-contagious-interview-npmjs-chalk-ultra-and-vitest-cli
The malicious npm packages `chalk-ultra` and `vitest-cli` execute a hidden downloader that steals developer credentials, source code, browser data, and cryptocurrency-wallet information. The payload can replace Chrome's MetaMask extension with a persistent trojanized version that captures the victim's wallet password. Ossprey links the packages to the DPRK Contagious Interview campaign through shared developer targeting, `jsonkeeper.com` payload delivery, detached execution, and the MetaMask-replacement technique, while noting that attribution of these specific packages remains unconfirmed. Affected systems should be treated as compromised and their credentials and wallet seed phrases rotated.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 138.201.140.23 | 2026-06-23 | 2026-07-02 |