HexEval Loader is a hex-encoded JavaScript malware loader used in DPRK-linked software supply chain activity associated with the Contagious Interview operation. It has been distributed via malicious and typosquatted npm packages targeting developers and job seekers. When a victim installs a malicious package, the loader executes during package installation, collects host metadata, decodes follow-on JavaScript, and communicates with hardcoded command-and-control infrastructure, including Vercel-hosted endpoints. The C2 can identify the geographical location of a victim host based on request headers, execution environment, and runtime conditions, and HexEval Loader has been observed exfiltrating victim data via HTTPS POST requests to its C2 servers. It executes malicious JavaScript code and, when triggered, fetches and runs BeaverTail as a second-stage payload; BeaverTail is described in the content as an infostealer/loader linked to DPRK attackers and can lead to deployment of InvisibleFerret. The campaign is tied to North Korean state-backed activity and specifically targets developer ecosystems through npm package abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... HexEval Loader ... (v1.0) ...
HexEval Loader (v1.0)
A previously observed malware dropper/loader used in earlier Contagious Interview npm supply-chain activity; referenced as being reused alongside XORIndex Loader.
HexEval Loader is a hex-encoded JavaScript loader embedded in malicious npm packages. Upon installation, it collects host metadata, decodes and executes a follow-on script, and fetches the BeaverTail infostealer as a second-stage payload. It is designed to evade static analysis and facilitate multi-stage attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.