North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages post, april 5, 2025april 7, 2025 The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader. “These latest samples employ hexadecimal string encoding to evade automated detection systems and manual code audits, signaling a variation in the threat actors’ obfuscation techniques,” Socket security researcher Kirill Boychenko said in a report. North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages: North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages vulnerability 2025North Korea