{"id":549,"date":"2025-04-05T08:53:12","date_gmt":"2025-04-05T06:53:12","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=549"},"modified":"2025-04-07T08:53:55","modified_gmt":"2025-04-07T06:53:55","slug":"north-korean-hackers-deploy-beavertail-malware-via-11-malicious-npm-packages","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/04\/05\/north-korean-hackers-deploy-beavertail-malware-via-11-malicious-npm-packages\/","title":{"rendered":"North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The North Korean threat actors behind the ongoing&nbsp;<a href=\"https:\/\/thehackernews.com\/2025\/04\/lazarus-group-targets-job-seekers-with.html\" rel=\"noreferrer noopener\" target=\"_blank\">Contagious Interview<\/a>&nbsp;campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;These latest samples employ hexadecimal string encoding to evade automated detection systems and manual code audits, signaling a variation in the threat actors&#8217; obfuscation techniques,&#8221; Socket security researcher Kirill Boychenko&nbsp;<a href=\"https:\/\/socket.dev\/blog\/lazarus-expands-malicious-npm-campaign-11-new-packages-add-malware-loaders-and-bitbucket\" rel=\"noreferrer noopener\" target=\"_blank\">said<\/a>&nbsp;in a report.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/04\/05\/north-korean-hackers-deploy-beavertail-malware-via-11-malicious-npm-packages\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2025\/04\/north-korean-hackers-deploy-beavertail.html\">North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages<\/a><span class=\"screen-reader-text\">: North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>The North Korean threat actors behind the ongoing&nbsp;Contagious Interview&nbsp;campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader. &#8220;These latest samples employ hexadecimal string encoding to evade automated detection systems and&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[40,39],"class_list":["post-549","post","type-post","status-publish","format-standard","hentry","category-vulnerability","tag-40","tag-north-korea"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/549","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=549"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/549\/revisions"}],"predecessor-version":[{"id":550,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/549\/revisions\/550"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=549"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=549"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=549"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}