header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

GoPlus Alert: North Korean Hackers Distribute Remote Access Trojan via Malicious npm Package

BlockBeats News, March 3rd, the GoPlus Chinese community issued a reminder, North Korean hackers published a set of 26 malicious packages to the npm registry, each of which comes with an installation script (install.js). This script will automatically execute during the package installation process, triggering the execution of malicious code located in "vendor/scrypt-js/version.js". The malicious code will download and run a remote access trojan (RAT) through the same malicious URL, carrying out malicious activities such as keylogging, clipboard theft, browser credential harvesting, TruffleHog secret scanning, Git repository and SSH key theft. This incident is linked to a North Korean hacker operation named "Famous Chollima".

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish