#StegaBin
Incident/Operation
StegaBin is a February 2026 wave of North Korea's Contagious Interview campaign, attributed with high confidence to Famous Chollima under the broader Lazarus umbrella. Twenty-six malicious npm packages targeted developers through install scripts and multistage payload delivery, using character-level text steganography in Pastebin content as a dead-drop mechanism for resolving command-and-control infrastructure. Platform-specific shell stages ultimately installed a remote-access trojan and a nine-module stealer that harvested development secrets, source repositories, SSH material, browser credentials, clipboard data, and local configuration. The packages and associated infrastructure were removed after discovery.
-
2
Tagged Reports
-
2
Unique Authors
-
11
Active Days