[Subscribe Now] Track A-Level Transparency Project Biweekly Report and Discover the Top 1% of Projects
API Download the RootData App

GoPlus: Beware of 26 malware packages released by North Korean hackers that can remotely download and execute trojans

Mar 3, 2026 16:33:05

Share to

GoPlus Chinese community issued a warning on platform X, stating that North Korean hackers have published a set of 26 malicious packages to the npm registry. These malicious packages come with an installation script ("install.js") that automatically executes during the package installation process, running malicious code located in "vendor/scrypt-js/version.js".

The malicious code downloads and executes a remote access trojan (RAT) via the same malicious URL, implementing malicious activities such as keylogging, clipboard theft, browser credential collection, TruffleHog secret scanning of Git repositories, and SSH key theft. This incident is related to a North Korean hacking activity known as "Famous Chollima".

Recent Fundraising

More
$5M Mar 12
-- Mar 11
$5M Mar 11

New Tokens

More
Mar 11
Mar 8
Mar 4

Latest Updates on 𝕏

More