#ApacheLicense
~Socket~
North Korean actors are deploying RATs via malicious packages across npm, PyPI, Go, Rust, and Packagist.
-
IOCs: 66. 45. 225. 94, apachelicense. vercel. app, logkit-tau. vercel. app
-
#DPRK #Malware #ThreatIntel
NK Contagious Interview Supply Chain Attack
socket.dev
April 9, 2026 at 4:08 AM
November 21, 2025 at 11:01 AM
North Korean threat actors distributed over 1,000 malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist, using staged loaders and RAT capabilities to target open-source ecosystems. #NorthKorea #SupplyChain #OpenSourceSecurity
North Korea’s Contagious Interview Campaign Spreads Across 5...
Contagious Interview published malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist that impersonated legitimate developer tooling and acted as staged loaders to fetch and execute second-stage payloads. The cluster includes a Windows-heavy variant (license-utils-kit) with full RAT capabilities and leverages infrastructure such as apachelicense[.]vercel[.]app and 66[.]45[.]225[.]94 for delivery. #ContagiousInterview #license-utils-kit
www.hendryadrian.com
April 9, 2026 at 10:30 AM
March 6, 2025 at 5:35 AM