{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@kolbo/mcp-1.57.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":["Lazarus Group","HIDDEN COBRA","LABYRINTH CHOLLIMA","Diamond Sleet","Zinc"],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@kolbo/mcp (1.57.1)","agentgui (1.0.1127)","godot-kit (1.0.1786316795)","envpack-conf (1.0.1)","postcss-initial-provider (3.0.4)","tailwindcss-motion-advanced (1.0.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eOn August 10, 2026, Sonatype Research Labs identified six malicious npm packages associated with the DPRK-linked Contagious Interview campaign. The threat actors are using two delivery vectors: hijacking existing, trusted legitimate packages and publishing new malicious packages. Affected packages include @kolbo/mcp (1.57.1), agentgui (1.0.1127), godot-kit (1.0.1786316795), envpack-conf (1.0.1), postcss-initial-provider (3.0.4), and tailwindcss-motion-advanced (1.0.1).\u003c/p\u003e\n\u003cp\u003eThe malware employs the \u0026quot;NullReceiver\u0026quot; technique, which utilizes the Ethereum blockchain as a dead-drop mechanism to resolve C2 infrastructure. Upon execution, the loader queries Ethereum RPC providers or the Blockscout API for outbound transactions from an attacker-controlled wallet. The recipient address of the transaction is decoded into IPv4 addresses for C2 communication. The loader then retrieves secondary JavaScript payloads from /0x/cls or /0x/ls endpoints, which are decoded via Base64/XOR and executed using eval() or detached child processes. This approach ensures high resiliency in maintaining C2 connections.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker hijacks legitimate npm package source code or publishes new packages containing a malicious loader script.\u003c/li\u003e\n\u003cli\u003eVictim installs the malicious package via npm, triggering the loader upon package initialization.\u003c/li\u003e\n\u003cli\u003eMalware queries Ethereum RPC endpoints (e.g., Infura, Alchemy) or the Blockscout API to identify a specific wallet transaction.\u003c/li\u003e\n\u003cli\u003eMalware reads the transaction recipient address and decodes the embedded bytes to retrieve primary and secondary C2 server IP addresses.\u003c/li\u003e\n\u003cli\u003eMalware performs an HTTP GET or HEAD request to the C2 infrastructure, potentially using the X-Payload-B64 header to receive an encoded payload.\u003c/li\u003e\n\u003cli\u003eMalware Base64-decodes and XOR-decrypts the received payload in memory.\u003c/li\u003e\n\u003cli\u003eMalware executes the decrypted payload using eval() within the active Node.js process or by spawning detached Node.js child processes for persistence and further staging.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign leverages trusted supply chain components to gain code execution within development and production environments. By using hijacked packages, the attackers can bypass standard dependency review processes. Successful exploitation leads to unauthorized code execution, allowing the Lazarus Group to perform data exfiltration, establish long-term persistence, or deploy further malicious stages within an organization's internal infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePerform a recursive audit of node_modules to identify the presence of the six affected npm packages listed in this brief.\u003c/li\u003e\n\u003cli\u003eRemove all identified packages immediately and review package-lock.json files to ensure malicious dependencies are not restored during CI/CD builds.\u003c/li\u003e\n\u003cli\u003eMonitor network egress for unexpected queries to Ethereum RPC API providers (e.g., nodes at infura.io, alchemy.com) or blockscout.com originating from Node.js applications.\u003c/li\u003e\n\u003cli\u003eInvestigate any npm packages that contain obfuscated code or late-injected logic within existing utility files (e.g., utils.min.js or database.js).\u003c/li\u003e\n\u003cli\u003eImplement dependency pinning and checksum verification for all npm packages to detect unauthorized modifications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-10T19:33:01Z","date_published":"2026-08-10T19:33:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-npm-nullreceiver/","summary":"The Lazarus Group is distributing malicious npm packages that use Ethereum blockchain transaction data to resolve C2 infrastructure and download secondary JavaScript payloads.","title":"DPRK-Linked Lazarus Group Campaign Distributing Malware via npm Packages","url":"https://feed.craftedsignal.io/briefs/2026-08-npm-nullreceiver/"}],"language":"en","title":"CraftedSignal Threat Feed - @Kolbo/Mcp (1.57.1)","version":"https://jsonfeed.org/version/1.1"}