Researchers reported the first confirmed appearance of the PylangGhost remote access trojan on the npm registry, where it was hidden in two malicious JavaScript packages: @jaime9008/math-service and react-refresh-update. The activity has been linked to FAMOUS CHOLLIMA, a North Korean state-sponsored threat group previously associated with developer-focused social engineering and trojanized software campaigns. The packages were reportedly uploaded by the user jaime9008, tied to the email jaimeandujo086[@]gmail.com, and contained a PylangGhost loader embedded in files including runtime.js, babel.js, and lib/lib.js.
The reported campaign used the hardcoded identifier "ML2J" and communicated with infrastructure including malicanbur[.]pro and 173.211.46[.]22:8080. The reporting indicates the npm activity represents an escalation of software supply chain targeting aimed at developers and development pipelines, extending a malware family that had previously been disclosed by Cisco Talos and attributed to the same DPRK-linked actor. A social post amplifying the Kmsec finding is consistent with that same event, while separate posts about Konni spear-phishing and KakaoTalk-linked activity describe a different DPRK-related campaign and are not part of this incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers reported the first observed instance of the North Korea-linked PylangGhost RAT on the npm registry and attributed the activity to FAMOUS CHOLLIMA. The report also disclosed campaign details including the "ML2J" identifier and infrastructure such as malicanbur[.]pro and 173.211.46[.]22:8080.
In early 2026, the npm user "jaime9008" published two malicious JavaScript packages, @jaime9008/math-service and react-refresh-update, that contained a loader for the PylangGhost remote access trojan. The packages targeted Windows, macOS, and Linux systems as part of a software supply chain campaign.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.