#HexEval
Malware/Tool
2025-06-25 • Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages
HexEval is a hex-encoded JavaScript loader embedded in malicious npm packages used in a DPRK-linked software-supply-chain campaign. Installation triggers collection of host metadata, decoding of a follow-on script, and, when campaign conditions are met, retrieval and execution of the BeaverTail information stealer. BeaverTail can then reference the InvisibleFerret backdoor. By fetching later stages on demand instead of embedding them directly, HexEval reduces obvious malicious content in the package and complicates static scanning and manual review.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days