Socket's threat research team uncovered 26 malicious npm packages linked to North Korea's FAMOUS CHOLLIMA (Lazarus Group) Contagious Interview campaign. Dubbed 'StegaBin,' the packages use character-level steganography hidden inside Pastebin essays to conceal C2 infrastructure across 31 Vercel deployments. The infection chain
•15m read time• From socket.dev
Table of contents
At a Glance #The Packages #Infection Chain #The Payload: A 9-Module Infostealer Toolkit #Module 1 — VSCode Persistence ( vs ) #Module 2 — Keylogger + Clipboard Stealer ( clip ) #Module 4 — Crypto Wallet Stealer ( j ) #Module 5 — Sensitive File Search & Exfiltration RAT ( z ) #Module 6 — Sensitive File Search & Exfiltration ( n ) #Module 7 — TruffleHog Secret Scanner ( truffle ) #Module 8 — Git Repository + SSH Key Theft ( git ) #Outlook and Recommendations #Acknowledgements #Shared IOCs Across All Modules #Full IOC List #Sort: