North Korean Hackers Weaponize 67 npm Packages to Deploy XORIndex Malware

The Socket Threat Research Team has identified a major escalation in North Korean cyberattacks on the open-source ecosystem, as threat actors behind the “Contagious Interview” operation deploy a new malware loader named XORIndex.

This fresh wave of activity intensifies a campaign previously exposed in June 2025, which featured the HexEval Loader, marking a dual-pronged threat against global developers, DevOps professionals, and individual users through software supply chain compromise.

In this latest surge, the attackers planted 67 malicious npm packages, collectively downloaded over 17,000 times, with at least 27 packages still actively distributed via the npm registry at the time of reporting. The coordinated campaign exhibits a persistent “whack-a-mole” pattern.

Whenever defenders identify and remove malicious packages, the adversaries swiftly upload new variants often using similar naming conventions, code structures, and command-and-control infrastructure. Both the XORIndex and HexEval Loader operations function in parallel.

XORIndex has surpassed 9,000 downloads in just over a month, while the HexEval Loader continues its deployment with more than 8,000 new infections within discovered packages.

Technical Breakdown

The newly discovered XORIndex Loader, so named for its XOR-based obfuscated strings and index-driven code hiding, is purpose-built to evade static detection.

XORIndex Malware
XORIndex Loader variant

Upon installation, the loader collects host metadata including hostname, username, OS, external IP, and geolocation then exfiltrates this data to hardcoded C2 endpoints.

It next executes arbitrary JavaScript via eval(), typically loading the BeaverTail second-stage malware.

XORIndex targets developers within the Node.js ecosystem, but its malware executes on Windows, macOS, and Linux alike.

BeaverTail, the main second-stage payload, specializes in harvesting secrets from cryptocurrency wallets, browser extension directories, and other sensitive files.

The malware archives results into a .zip file, exfiltrates it to a North Korea-controlled server, and subsequently attempts to fetch the InvisibleFerret backdoor for deeper persistence and control.

The technical progression of XORIndex Loader variants, from initial un-obfuscated prototypes (such as postcss-preloader) to the sophisticated, memory-evasive loaders found in cronek and eth-auditlog, reflects a deliberate and rapid adaptation cycle.

XORIndex Malware
obfuscated code in the cronek package.

Ongoing Bypasses

North Korean attackers maintain resilience by recycling known loader patterns, quickly registering new npm maintainer identities, and rotating through legitimate infrastructure like Vercel for their C2 servers.

Their approach mixes subtle obfuscation, post-install remote code execution, and memory-only payloads, complicating incident detection and response.

Developers, DevOps practitioners, and organizations handling cryptocurrency are especially at risk due to their elevated access and frequent dependence on open-source packages.

Socket recommends integrating real-time supply chain monitoring into developer workflows, utilizing tools like the Socket GitHub App for pre-merge scanning, its CLI for installation-time checks, and browser extensions to surface package risk metrics.

Meanwhile, security teams must treat npm package compromise as a persistent, state-backed threat and remain vigilant, as the attackers continue to iterate on loader designs and expand their malware toolkit.

Indicators of Compromise (IOCs)

Malicious Packages (XORIndex Loader)npm Aliases (XORIndex)Emails (XORIndex)Malicious Packages (HexEval Loader)npm Aliases (HexEval)Emails (HexEval)C2 Endpoints
vite-meta-pluginh96452582h96452582@gmail[.]comnextjs-https-supertestdenniswinterdenniswinter727@outlook[.]comhttps://soc-log[.]vercel[.]app/api/ipcheck
vite-postcss-toolsdevin-ta39devin.s@gedu[.]demo[.]ta-39[.]comnextjs-package-purifymagalhaesbruno236magalhaesbruno236@gmail[.]comhttps://1215[.]vercel[.]app/api/ipcheck
pretty-chalkcsilvagalaxycsilvagalaxy87@gmail[.]comjsonslicerbacksonblaujacksonblau11ai@gmail[.]comhttps://log-writter[.]vercel[.]app/api/ipcheck
vite-usageitalisson_devsouzaporto800@gmail[.]comnode-mongo-ormjinpingjinping0821@outlook[.]comhttps://process-log-update[.]vercel[.]app/api/ipcheck
ecom-configdmytryidmytroputko@gmail[.]comtailwind-config-pluginoleksandr522oleksandrkazadaiev522@gmail[.]comhttps://api[.]npoint[.]io/1f901a22daea7694face
flowframedrgrudrgru854@gmail[.]comnodestream-loghera0204hera19970204@outlook[.]com144[.]217[.]86[.]88
proc-loggerahmadbahaiahmadbahai07@gmail[.]comvite-lightparsekingxianstarimanwdr30@hotmail[.]com

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant updates

Mandvi
Mandvi
Mandvi is a Security Reporter covering data breaches, malware, cyberattacks, data leaks, and more at Cyber Press.

Trending News

Related Stories