XORIndex Loader is a malware loader associated with the North Korean state-backed Contagious Interview operation. It was observed in a campaign in which attackers uploaded 67 malicious npm packages, collectively downloaded more than 17,000 times, using package names that mimicked legitimate projects. When a victim installed one of these packages, a postinstall script launched XORIndex Loader. The malware is described as a novel tool used in parallel with HexEval Loader in past attacks.
XORIndex Loader profiles infected hosts, including identifying the geographical location of a victim host, and sends victim profiling data to a hardcoded command-and-control address hosted on Vercel infrastructure. It has exfiltrated victim data to its C2 using HTTPS POST requests. The C2 responds with one or more JavaScript payloads, which XORIndex Loader executes via eval(); the malware is also noted as executing malicious JavaScript code. Its strings have been obfuscated using ASCII buffers and TextDecoder.
In the reported activity, the JavaScript payloads delivered by XORIndex Loader were typically BeaverTail and the InvisibleFerret backdoor. These payloads provided access to compromised developer systems, enabled data exfiltration, and supported download of additional payloads. The campaign primarily targeted developers through malicious npm packages and fake job-offer lures, with objectives including collection of sensitive information for follow-on breaches and theft of cryptocurrency assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
"Amadey does not run any tasks or install additional malware if the victim machine is based in Russia"; "DarkGate queries system locale information... determine if the malware is executing in Russian-speaking countries"; "Ragnar Locker checks... GetLocaleInfoW and doesn't encrypt files if it finds a former Soviet country"; "Saint Bot has conducted system locale checks..."
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... XORIndex Loader ... (v1.0) ...
XORIndex Loader (v1.0)
A newly observed JavaScript malware loader delivered via malicious npm packages. It profiles the host and sends victim data to a hardcoded C2 (hosted on Vercel), then receives and executes additional JavaScript payloads via eval(), commonly delivering BeaverTail and InvisibleFerret.
Loader malware that obfuscates strings using ASCII buffers and TextDecoder.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.