Researchers reported that the npm package jsonspack was used in a DPRK-linked software supply chain campaign to deliver a multi-tenant Node.js remote access trojan (RAT). The malicious package targeted developers and downstream environments through the open-source ecosystem, turning a seemingly legitimate dependency into an initial access vector. The operation reflects a broader pattern of North Korean threat activity that abuses trusted developer workflows and package repositories to gain footholds inside victim networks.
The malware’s tradecraft aligned with known ATT&CK behaviors including Data Obfuscation (T1001) to conceal command-and-control traffic and Execution Guardrails (T1480) to restrict payload execution to intended targets and reduce exposure during analysis. Those techniques are commonly used to blend malicious communications into normal web activity, compress or encrypt exchanged data, and enforce environment checks before running. Together, the references indicate a carefully controlled supply chain intrusion in which a trojanized Node.js package was used to selectively deploy and operate covert remote access capability.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Panther published research on a supply-chain campaign involving the npm package jsonspack, describing it as a DPRK-linked Node.js RAT operation. The reference identifies this as the disclosure of the campaign and its tooling.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
panther.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.