Threat reportSupply ChainTL-2026-0559
DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT
DPRK npm Supply Chain Attack (TL-2026-0559), also tracked as terminal-logger-utils campaign, is a high-severity supply-chain compromise, first published 2026-05-22. It is attributed to Contagious Interview (North Korea) with high confidence, affects npm registry (OpenJS / GitHub) terminal-logger-utils, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 26MITRE ATT&CK
- Actors
- 1Contagious Interview
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0559
- Threat ID
- TL-2026-0559
- Also known as
- terminal-logger-utils campaign, Lordplay/system-releases campaign, jpeek895 npm cluster
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Contagious Interview
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, software-development, cryptocurrency, financial, fintech, web3, ai-ml, devops, cloud, open-source
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in DPRK npm Supply Chain Attack
Malware and tooling: terminal-logger-utils SEA implant, Custom Node.js SEA implant (keylogger+infostealer+RAT) over WebSocket, Node.js Single Executable Application (SEA)
How DPRK npm Supply Chain Attack works
North Korea-linked npm uploader jpeek895 (and three colluding accounts) published terminal-logger-utils plus three dependents (pretty-logger-utils, ts-logger-pack, pinno-loggers) whose postinstall hook executes utils.cjs, an obfuscated multi-stage dropper. utils.cjs fingerprints the host OS, pulls a Node.js Single Executable Application (SEA) from the attacker-controlled Hugging Face repository Lordplay/system-releases, and establishes triple persistence on Windows (%LOCALAPPDATA%\MicrosoftSystem64 + hidden VBS launcher + scheduled task + HKCU\...\Run key). The implant fuses keylogger, infostealer, and RAT functionality — exfiltrating Telegram session data, SSH keys, cryptocurrency wallets, browser credentials, cloud configs, and environment variables — with HTTP keystroke exfil to /api/validate/keyboard-events and a WebSocket C2 at 195.201.194.107 for full interactive machine control. The campaign is a novel TTP evolution: abusing Hugging Face — a trusted AI/ML platform — as both payload-hosting CDN and self-update channel to evade allowlist-based egress controls.
On 2026-05-22, OX Security disclosed an active North Korea-aligned npm supply chain attack centered on the package terminal-logger-utils, uploaded by npm account jpeek895 — an account previously flagged by independent researcher kmsec.uk as part of the DPRK npm-package cluster. Three dependent packages — pretty-logger-utils, ts-logger-pack, pinno-loggers — were published by collaborating accounts jpeek886, pvnd3540749, and yggedd817513 to inflate apparent legitimacy and broaden the install footprint.
Infection Chain. When a developer runs `npm install terminal-logger-utils` (directly or transitively via one of the dependents), npm's `postinstall` lifecycle hook executes the bundled dropper `utils.cjs`. utils.cjs is a heavily obfuscated CommonJS module that performs OS dispatch (Windows / macOS / Linux), then issues an HTTPS request to the Hugging Face Hub repository `Lordplay/system-releases` (a legitimate-looking AI model hosting endpoint) to download an OS-specific Node.js Single Executable Application (SEA) binary. The SEA payload bundles a Node runtime with the malicious JavaScript, eliminating any requirement for a developer-side Node installation and reducing AV/EDR detection of the script body.
Windows Persistence. On Windows hosts the second-stage installs itself to `%LOCALAPPDATA%\MicrosoftSystem64\` — a path chosen to masquerade as a legitimate Microsoft system component. Three persistence mechanisms are established in parallel: (1) a hidden VBScript launcher dropped into the install directory that re-launches the SEA binary on user logon, (2) a Windows Scheduled Task registered under Task Scheduler that re-executes the binary at logon and on a recurring interval, and (3) an `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key as a fallback autostart vector. The triple-redundant persistence is characteristic of DPRK developer-targeting clusters tracked under names such as Contagious Interview / DEV#POPPER / Famous Chollima.
Implant Capabilities. The SEA second-stage is a fused keylogger + infostealer + RAT. Keystroke capture occurs continuously and is exfiltrated over plain HTTP POST to the path `/api/validate/keyboard-events` on attacker infrastructure. Stealer modules target high-value developer artifacts: Telegram `tdata` session folders (allowing full account hijack without 2FA prompt), `~/.ssh/` keys, cryptocurrency wallet files for major hot-wallet clients (MetaMask, Phantom, Exodus, Electrum, etc.), browser-saved passwords / cookies / autofill (Chrome, Edge, Brave, Firefox profile directories), cloud configuration files (`.aws/credentials`, `gcloud` config, `kube/config`), and shell environment variables that frequently contain API tokens and database URIs. The RAT module opens a WebSocket back to `195.201.194.107` (a Hetzner-range IP) supporting interactive commands: arbitrary shell command execution, file read/write, screenshot capture, simulated input injection, and self-update via fetching new SEA blobs from the Hugging Face repository.
Hugging Face Abuse. The novel element is the abuse of Hugging Face as a malware delivery and update CDN. Hugging Face is allowlisted in many enterprise egress policies because of legitimate ML/AI workloads, and its content-addressable storage backed by Git-LFS provides versioned, high-throughput, TLS-protected delivery. The attackers benefit from: (a) trust inheritance from the platform brand, (b) bypassing URL-reputation-only blocking, (c) free hosting and bandwidth, (d) the ability to push updates by simply git-pushing new SEA blobs to `Lordplay/system-releases`, and (e) plausible deniability — the repo can be styled to look like a legitimate model release. The same pattern was previously observed with the abuse of GitHub Releases, Cloudflare Pages, and Bitbucket; Hugging Face is the next logical evolution.
Attribution. Direct attribution rests on continuity between jpeek895 and prior DPRK npm clusters catalogued by kmsec.uk. The package-naming convention (developer-tool typosquats targeting npm/TypeScript ecosystem users), the multi-account publish-and-prop pattern, the developer-focused exfiltration targets (Telegram for social-engineering pivots, crypto wallets for revenue, cloud credentials for downstream intrusion), and the triple Windows persistence stack all align with the Contagious Interview / Famous Chollima TTP cluster operated by units under the DPRK Reconnaissance General Bureau (RGB) — overlapping with Lazarus subgroup tracking. Attribution confidence: HIGH.
MITRE ATT&CK techniques used in TL-2026-0559
Collection
T1005 Data from Local System; T1113 Screen Capture
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Credential Access
T1056 Input Capture; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
Impact
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities
Affected products and versions in DPRK npm Supply Chain Attack
- npm registry (OpenJS / GitHub) — terminal-logger-utils
Vulnerable versions: all published versions - npm registry (OpenJS / GitHub) — pretty-logger-utils
Vulnerable versions: all published versions - npm registry (OpenJS / GitHub) — ts-logger-pack
Vulnerable versions: all published versions - npm registry (OpenJS / GitHub) — pinno-loggers
Vulnerable versions: all published versions - Any Node.js developer workstation — Windows, macOS, Linux (OS-dispatched payloads)
Vulnerable versions: all
Remediation for DPRK npm Supply Chain Attack
Patches
- Report and remove the malicious packages from the npm registry (npm-security); ensure transitively pinned versions are purged from organization lockfiles.
Immediate actions
- Remove terminal-logger-utils, pretty-logger-utils, ts-logger-pack, and pinno-loggers from all package.json and lockfiles; rebuild node_modules from a clean cache.
- Block egress to 195.201.194.107 at perimeter firewalls and EDR network policy.
- Block or alert on outbound HTTPS to huggingface.co paths matching Lordplay/system-releases and any unknown user/org repo containing executable binary blobs (.exe, .bin, SEA artifacts).
- Hunt for %LOCALAPPDATA%\MicrosoftSystem64\ directory on all Windows developer endpoints; quarantine and forensicate any host where it exists.
- Audit HKCU\Software\Microsoft\Windows\CurrentVersion\Run for entries pointing into MicrosoftSystem64 or referencing .vbs launchers in LocalAppData.
- Audit Windows Scheduled Tasks for unsigned tasks launching binaries from %LOCALAPPDATA%.
- Rotate all developer credentials potentially exposed: SSH keys, AWS/GCP/Azure tokens, Telegram sessions, browser-saved passwords, cryptocurrency wallet seeds, npm tokens, GitHub PATs.
Workarounds
- Pin all npm dependencies to known-good versions in package-lock.json / pnpm-lock.yaml and refuse to upgrade until provenance is verifiable.
- Run `npm install` only inside ephemeral sandboxed containers; never on host developer machines that hold long-lived credentials.
Longer-term hardening
- Enforce npm postinstall script disablement in CI and on developer workstations (`npm config set ignore-scripts true`) and re-enable only for vetted dependencies.
- Adopt an internal npm proxy (Verdaccio, JFrog Artifactory, Sonatype Nexus, GitHub Packages) with allowlist-based publisher verification.
- Deploy EDR with behavioral detection for: postinstall spawning powershell/cmd, postinstall writing to LocalAppData, scheduled-task creation by node.exe, Run-key writes by node.exe.
- Egress allowlist Hugging Face only for ML/AI workloads; segregate dev workstations from the ML egress profile or require proxy inspection of large LFS pulls.
- Adopt Sigstore-style cryptographic signing or npm package provenance attestations as a gating policy for production dependencies.
Weaknesses (CWE) in DPRK npm Supply Chain Attack
Timeline of DPRK npm Supply Chain Attack
- Hugging Face Hub identified as a new trusted-platform abuse vector for DPRK developer-targeting malware delivery — an evolution beyond prior abuse of GitHub Releases, Bitbucket, and Cloudflare Pages.
- Campaign confirmed active: malicious packages observed live on the npm registry under the listed accounts; Hugging Face repository Lordplay/system-releases serving SEA binaries; WebSocket C2 195.201.194.107 reachable.
- Threadlinqs Intelligence publishes TL-2026-0559 with full MITRE ATT&CK mapping, IOC catalogue, and detection coverage for SOC consumption.
- Attribution to DPRK established via continuity with prior jpeek895 activity previously documented by independent researcher kmsec.uk.
- Package list (terminal-logger-utils + 3 dependents), npm uploader accounts (jpeek895, jpeek886, pvnd3540749, yggedd817513), C2 IP 195.201.194.107, and Hugging Face repository Lordplay/system-releases publicly catalogued.
- OX Security publishes research on the terminal-logger-utils campaign; Cyber Security News covers the disclosure, exposing Hugging Face as the second-stage delivery platform.
- As of 2026-05-29, this DPRK (Famous Chollima/Contagious Interview) npm supply-chain attack remains active: disclosed only days earlier (2026-05-22 OX Security; JFrog 04-23 on the same Lordplay/system-releases repo), with no confirmed takedown of the packages, Hugging Face CDN, or C2 195.201.194.107. The actor is escalating, with 204 malicious npm releases Apr 25-May 25, 2026.
Sources cited for DPRK npm Supply Chain Attack
- Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack
- OX Security — research home (primary research source cited by CSN)
- kmsec.uk — DPRK npm package research and jpeek895 prior attribution
- kmsec.uk DPRK npm packages tracker
- Node.js Single Executable Applications documentation
- MITRE ATT&CK — T1195.002 Compromise Software Supply Chain
- MITRE ATT&CK — T1102 Web Service (legitimate platform abuse)
Detection coverage for TL-2026-0559
As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0559 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.