malicious packages

Winsage
August 6, 2024
GuardDog software identified two malicious npm packages, harthat-hash and harthat-api, linked to a North Korean threat actor group called "Stressed Pungsan," which has connections to Microsoft's MOONSTONE SLEET. These packages were uploaded by a user named nagasiren978 on July 7, 2024, and were designed to download additional malware from a suspected North Korean command and control server. The packages utilized a pre-install script to download and execute a harmful DLL via rundll32, while also self-destructing to evade detection. The harthat-api package impersonated the legitimate Hardhat package and modified its package.json file to conceal its malicious intent. The malicious DLL appeared innocuous but is suspected to contain harmful functionality. The threat actors compromised targets using the packages harthat-api-v1.3.1.zip and harthat-hash-v1.3.3.zip, traced back to the IP address 142.111.77.196. Indicators of compromise include the filename Temp.b (package.db) and its SHA256 hash, d2a74db6b9c900ad29a81432af72eee8ed4e22bf61055e7e8f7a5f1a33778277.
Search