#XORIndex

Malware/Tool

2025-07-15 • Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader

XORIndex Loader is malware used by North Korean actors in the Contagious Interview software-supply-chain campaign. Its name reflects XOR-encoded strings and index-based obfuscation. Operators distributed it through 28 malicious npm packages across 18 accounts as part of a larger wave of 67 packages that accumulated more than 17,000 downloads. The campaign followed earlier use of HexEval Loader, with reported packages quickly replaced by new variants. XORIndex collects host data, decodes follow-on scripts, and downloads BeaverTail, which can deliver the InvisibleFerret backdoor. MITRE ATT&CK S1248.

Tagged Reports

« Back