StegaBin is a software supply-chain malware campaign delivered through 26 malicious typosquatted npm packages that impersonate developer tools and popular libraries. The packages execute a hidden install hook during npm installation, typically via node ./scripts/test/install.js, which launches an obfuscated loader at vendor/scrypt-js/version.js. The loader uses Pastebin-based steganographic dead-drop resolvers to recover command-and-control infrastructure from benign-looking essay text, then pivots through Vercel-hosted domains to fetch platform-specific payloads for Windows, Linux, and macOS. Reported stage endpoints include /api/w, /api/l, and /api/m on Vercel infrastructure, and the final RAT was observed connecting to 103.106.67.63:1244, with an additional WebSocket channel on port 1247.
The malware ultimately installs a cross-platform information-stealing remote access trojan and automatically deploys a nine-module infostealer toolkit. Reported capabilities include keylogging, clipboard capture, credential theft, browser data theft, cryptocurrency wallet and extension theft, Git repository and SSH key theft, filesystem searching for secrets such as .env files and mnemonics, downloading and running TruffleHog to scan for exposed secrets, persistence, remote shell access, and file exfiltration. Persistence was observed through a malicious VSCode tasks.json configured with runOn: folderOpen, allowing infected project directories to retrigger execution when opened. The campaign was designed to preserve expected package functionality by declaring the legitimate typosquatted package as a dependency, reducing suspicion while compromising developer workstations.
The activity is tracked as StegaBin and is described as part of, or an evolution of, the Contagious Interview campaign. Multiple reports assess the tradecraft, infrastructure, and TTPs as consistent with the North Korea-aligned actor Famous Chollima, also associated with Lazarus Group activity. Targeting is centered on developers, with particular risk to source code, SSH material, browser credentials, tokens, VSCode settings, clipboard contents, Git data, and cryptocurrency-related assets. High-confidence indicators directly mentioned in the reporting include the loader path vendor/scrypt-js/version.js, Pastebin URLs pastebin.com/CJ5PrtNk, pastebin.com/0ec7i68M, and pastebin.com/DjDCxcsT, Vercel-hosted C2 infrastructure, and C2 IP 103.106.67.63.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Contagious Interview Campaign: Independent Analysis of the StegaBin Wave"
6 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
"Contagious Interview Campaign: Independent Analysis of the StegaBin Wave"
Multi-stage credential stealer delivered via malicious npm packages using Pastebin steganography for payload delivery/obfuscation.
Multi-stage credential-stealing malware delivered via malicious npm packages using Pastebin steganography.
Cross-platform information-stealing RAT delivered via illicit npm packages with an auto-executing install script. Uses Pastebin to obtain C2 (Vercel URLs), then retrieves OS-specific payloads (Windows/Linux/macOS). Reported modules support keylogging, credential theft, browser and cryptocurrency data exfiltration, downloading TruffleHog secrets scanner, and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.