Skip to main content
Mallory
Back to stories
package-repository-poisoningcredential-stealer-activityremote-access-implantcommand-and-control-method

Developer-Focused Supply Chain Malware via Malicious Open-Source Packages

Updated 5d agoFirst seen Feb 27, 202612 sources

Security researchers reported multiple software supply chain campaigns targeting developers through malicious packages in public repositories, aiming to steal credentials/secrets and establish persistent access that can later impact production environments. Socket disclosed a campaign dubbed StegaBin involving 26 malicious npm packages published over a two-day window that used a Pastebin “dead-drop” with character-level steganography to conceal C2 details, then resolved additional infrastructure across 31 Vercel deployments to deliver platform-specific shell payloads that install a RAT and a nine-module infostealer targeting VSCode data, SSH keys, git repositories, browser credential stores, clipboard contents, and other local secrets. Socket assessed the tradecraft as consistent with activity previously attributed to North Korea-aligned FAMOUS CHOLLIMA (Lazarus-linked) and noted rapid detection of the packages shortly after publication.

Separately, reporting highlighted four malicious NuGet packagesNCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_—that targeted ASP.NET developers by exfiltrating ASP.NET Identity data (users/roles/permissions) and enabling backdoors; the packages were published in August 2024, accumulated 4,500+ downloads, and were later removed. In that campaign, NCryptYo functioned as a dropper and proxy to an attacker-controlled C2, while DOMOAuth2_ and IRAOAuth2.0 handled data theft and backdoor rule delivery, and SimpleWriter_ enabled file writing and hidden process execution while masquerading as a PDF utility. Other items in the set described unrelated C2 tooling trends (a Polygon blockchain-based botnet loader and the Vshell C2 framework) and do not describe the same package-repository supply chain incidents.

Share:
Developer-Focused Supply Chain Malware via Malicious Open-Source Packages
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the earliest known activity through the most recent confirmed update.

12 EVENTS
Aug 12, 20242y ago

Malicious NuGet packages published to target ASP.NET developers

Four malicious NuGet packages — NCryptYo, DOMOAuth2_, IRAOAuth2.0, and SimpleWriter_ — were published between August 12 and 21, 2024, to compromise ASP.NET web application developers during development. The packages were designed to steal ASP.NET Identity data and establish persistent backdoors that could later provide access to production environments.

Feb 25, 20263mo ago

Malicious npm packages published in StegaBin campaign

A supply-chain campaign later dubbed StegaBin published 26 typosquatted malicious npm packages on February 25–26, 2026, targeting developers with install-time malware. The packages used obfuscated loaders, Pastebin-based steganography, and Vercel-hosted infrastructure to deliver cross-platform payloads.

Socket rapidly detects StegaBin packages after publication

Socket reported detecting the first malicious StegaBin package within two minutes of publication and all 26 packages within six minutes each. This early detection helped surface the campaign's infrastructure, payload delivery chain, and post-exploitation toolkit.

Feb 26, 20263mo ago

Researcher Kieran Miyamoto discloses 17 related malicious npm packages

On February 26, 2026, independent researcher Kieran Miyamoto disclosed 17 related malicious npm packages and described the Pastebin decoder technique used in the campaign. The disclosure corroborated broader findings about the npm supply-chain activity.

Feb 27, 20263mo ago

Socket discloses StegaBin campaign and links it to Famous Chollima

On February 27, 2026, Socket publicly reported the StegaBin campaign, detailing 26 malicious npm packages, Pastebin steganography for C2 resolution, Vercel-based routing, and a nine-module infostealer/RAT toolkit. Based on tradecraft and infrastructure overlap, Socket assessed the activity as consistent with the North Korea-aligned actor FAMOUS CHOLLIMA tied to the Lazarus Group.

Malicious NuGet packages removed after discovery

The four malicious NuGet packages targeting ASP.NET developers were removed from NuGet after being discovered. Before takedown, the campaign accumulated more than 4,500 downloads.

Mar 1, 20263mo ago

Backdoored axios npm releases tied to hijacked maintainer account

In March 2026, attackers hijacked an axios maintainer account and published backdoored npm package versions carrying a cross-platform RAT. Microsoft and Google later attributed the campaign to a North Korea-linked cluster, while Elastic Security Labs described the operation as highly coordinated and carefully prepared.

Trusted by default: The npm attack pattern security teams miss | perspective | SC Media
Mar 2, 20263mo ago

Researchers detail updated Contagious Interview npm tradecraft

By March 2, 2026, researchers described the StegaBin activity as a new iteration of the North Korea-linked Contagious Interview campaign. The reporting highlighted the actor's shift to Pastebin steganography and multi-stage Vercel routing, plus a separate newer technique using Google Drive to fetch next-stage JavaScript.

Mar 7, 20262mo ago

Socket identifies five malicious NuGet packages impersonating Chinese UI libraries

On 2026-03-07, Socket disclosed five malicious NuGet packages published by the account bmrxntfj that impersonated or typosquatted Chinese .NET libraries and delivered a .NET Reactor-protected infostealer. The campaign had used 224 package versions since at least September 2025, amassed about 64,784 downloads, and the packages were still available on NuGet when Socket said it submitted takedown requests.

5 Malicious NuGet Packages Impersonate Chinese UI Libraries ...
Apr 7, 20261mo ago

Socket links Contagious Interview to 1,700+ packages across five ecosystems

On April 7, 2026, Socket reported that a broader Contagious Interview software supply-chain cluster had spread across npm, PyPI, Go Modules, crates.io, and Packagist, encompassing more than 1,700 malicious packages. The report detailed shared publisher aliases, staged malware loaders, infrastructure on Vercel/Render and Google Drive, and noted that some packages and accounts were removed after reporting while others remained live.

North Korea’s Contagious Interview Campaign Spreads Across 5...
May 1, 202617d ago

Socket uncovers BufferZoneCorp RubyGems and Go modules supply-chain campaign

On 2026-05-01, Socket disclosed a software supply-chain campaign tied to the GitHub account BufferZoneCorp that used malicious Ruby gems and Go modules to steal secrets from developers, CI runners, and build environments. The report detailed credential theft, GitHub Actions and GOPROXY tampering, fake Go wrappers, and persistence via an added SSH key; Go Security blocked the identified malicious Go modules, while the Ruby gems and BufferZoneCorp account remained live at publication.

Malicious Ruby Gems and Go Modules Impersonate Developer Too...
May 11, 20267d ago

Socket reports compromise of 84 @tanstack npm package artifacts

On 2026-05-11, Socket disclosed that 84 npm package artifacts in the @tanstack namespace were compromised with credential-stealing malware targeting developer and CI/CD environments. The report linked the activity to the ongoing Mini Shai-Hulud campaign and said TanStack responded by unpublishing affected versions and shutting down publishing pipelines while investigating.

TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud...
SOURCE COVERAGE

Sources

12 references tracked. Mallory keeps watching after this page renders.

12 SOURCESView all
ScworldNews
May 13, 2026

Trusted by default: The npm attack pattern security teams miss | perspective | SC Media

scworld.com

Open source
Socket BlogNews
May 12, 2026

TanStack npm Packages Compromised in Ongoing Mini Shai-Hulud...

socket.dev

Open source
Cyber Security NewsNews
May 7, 2026

Malicious NuGet Packages Target Browser Credentials, SSH Keys, and Crypto Wallets

cybersecuritynews.com

Open source
Socket BlogNews
May 1, 2026

Malicious Ruby Gems and Go Modules Impersonate Developer Too...

socket.dev

Open source
The Hacker NewsNews
Apr 8, 2026

N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust

thehackernews.com

Open source
Socket BlogNews
Apr 7, 2026

North Korea’s Contagious Interview Campaign Spreads Across 5...

socket.dev

Open source
Socket BlogNews
Mar 7, 2026

5 Malicious NuGet Packages Impersonate Chinese UI Libraries ...

socket.dev

Open source
ScworldNews
Mar 3, 2026

Updated Contagious Interview campaign harnesses illicit npm packages for RAT delivery | brief | SC Media

scworld.com

Open source
Cyber Security NewsNews
Mar 3, 2026

New 'StegaBin' Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer

cybersecuritynews.com

Open source
The Hacker NewsNews
Mar 2, 2026

North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT

thehackernews.com

Open source
ScworldNews
Feb 27, 2026

Malicious NuGet packages target ASP.NET developers, steal sensitive data | brief | SC Media

scworld.com

Open source
Socket BlogNews
Feb 27, 2026

StegaBin: 26 Malicious npm Packages Use Pastebin Steganograp...

socket.dev

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Developer-Focused Supply Chain Malware via Malicious Open-Source Packages | Mallory