Image for Article: North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT

Article Details

Title
Article: North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT
Impact Score
6 / 10
AI Summary (Processed Content)

North Korean threat actors have published 26 malicious packages to the npm registry, masquerading as developer tools. The campaign, tracked as StegaBin and attributed to the Famous Chollima group, uses packages with install scripts that deploy a steganographic loader. This loader extracts hidden command-and-control URLs from seemingly benign Pastebin essays, ultimately delivering a credential stealer and remote access trojan. The malware targets developers by exfiltrating credentials, browser data, Git repositories, and SSH keys, and establishes persistence in tools like VS Code.

Original URL
https://thehackernews.com/2026/03/north-korean-hackers-publish-26-npm.html
Source Feed
The Hacker News
Published Date
2026-03-02 08:44
Fetched Date
2026-03-04 13:39
Processed Date
2026-03-04 13:59
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content