North Korean Hackers Weaponized 67 Malicious npm Packages to Deliver XORIndex Malware

North Korean threat actors have escalated their software supply chain attacks with the deployment of 67 malicious npm packages that collectively garnered over 17,000 downloads before detection. This latest campaign represents a significant expansion of the ongoing “Contagious Interview” operation, introducing a previously unreported malware loader dubbed XORIndex alongside the existing HexEval Loader infrastructure. The newly discovered XORIndexmalware, named for its distinctive use of XOR-encod...

Save to Folder

Choose a folder to save this article: