Threat reportSupply ChainTL-2026-0559

DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT

highACTIVE

DPRK npm Supply Chain Attack (TL-2026-0559), also tracked as terminal-logger-utils campaign, is a high-severity supply-chain compromise, first published 2026-05-22. It is attributed to Contagious Interview (North Korea) with high confidence, affects npm registry (OpenJS / GitHub) terminal-logger-utils, maps to 26 MITRE ATT&CK techniques (T1005, T1027, T1036), and is covered by 9 detection rules and 26 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
26MITRE ATT&CK
Actors
1Contagious Interview
Detection rules
9SPL · KQL · Sigma
IOCs
26Indicators of compromise

Key facts for TL-2026-0559

Threat ID
TL-2026-0559
Also known as
terminal-logger-utils campaign, Lordplay/system-releases campaign, jpeek895 npm cluster
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Contagious Interview
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, software-development, cryptocurrency, financial, fintech, web3, ai-ml, devops, cloud, open-source
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
26

Malware and tooling in DPRK npm Supply Chain Attack

Malware and tooling: terminal-logger-utils SEA implant, Custom Node.js SEA implant (keylogger+infostealer+RAT) over WebSocket, Node.js Single Executable Application (SEA)

How DPRK npm Supply Chain Attack works

North Korea-linked npm uploader jpeek895 (and three colluding accounts) published terminal-logger-utils plus three dependents (pretty-logger-utils, ts-logger-pack, pinno-loggers) whose postinstall hook executes utils.cjs, an obfuscated multi-stage dropper. utils.cjs fingerprints the host OS, pulls a Node.js Single Executable Application (SEA) from the attacker-controlled Hugging Face repository Lordplay/system-releases, and establishes triple persistence on Windows (%LOCALAPPDATA%\MicrosoftSystem64 + hidden VBS launcher + scheduled task + HKCU\...\Run key). The implant fuses keylogger, infostealer, and RAT functionality — exfiltrating Telegram session data, SSH keys, cryptocurrency wallets, browser credentials, cloud configs, and environment variables — with HTTP keystroke exfil to /api/validate/keyboard-events and a WebSocket C2 at 195.201.194.107 for full interactive machine control. The campaign is a novel TTP evolution: abusing Hugging Face — a trusted AI/ML platform — as both payload-hosting CDN and self-update channel to evade allowlist-based egress controls.

On 2026-05-22, OX Security disclosed an active North Korea-aligned npm supply chain attack centered on the package terminal-logger-utils, uploaded by npm account jpeek895 — an account previously flagged by independent researcher kmsec.uk as part of the DPRK npm-package cluster. Three dependent packages — pretty-logger-utils, ts-logger-pack, pinno-loggers — were published by collaborating accounts jpeek886, pvnd3540749, and yggedd817513 to inflate apparent legitimacy and broaden the install footprint.

Infection Chain. When a developer runs `npm install terminal-logger-utils` (directly or transitively via one of the dependents), npm's `postinstall` lifecycle hook executes the bundled dropper `utils.cjs`. utils.cjs is a heavily obfuscated CommonJS module that performs OS dispatch (Windows / macOS / Linux), then issues an HTTPS request to the Hugging Face Hub repository `Lordplay/system-releases` (a legitimate-looking AI model hosting endpoint) to download an OS-specific Node.js Single Executable Application (SEA) binary. The SEA payload bundles a Node runtime with the malicious JavaScript, eliminating any requirement for a developer-side Node installation and reducing AV/EDR detection of the script body.

Windows Persistence. On Windows hosts the second-stage installs itself to `%LOCALAPPDATA%\MicrosoftSystem64\` — a path chosen to masquerade as a legitimate Microsoft system component. Three persistence mechanisms are established in parallel: (1) a hidden VBScript launcher dropped into the install directory that re-launches the SEA binary on user logon, (2) a Windows Scheduled Task registered under Task Scheduler that re-executes the binary at logon and on a recurring interval, and (3) an `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key as a fallback autostart vector. The triple-redundant persistence is characteristic of DPRK developer-targeting clusters tracked under names such as Contagious Interview / DEV#POPPER / Famous Chollima.

Implant Capabilities. The SEA second-stage is a fused keylogger + infostealer + RAT. Keystroke capture occurs continuously and is exfiltrated over plain HTTP POST to the path `/api/validate/keyboard-events` on attacker infrastructure. Stealer modules target high-value developer artifacts: Telegram `tdata` session folders (allowing full account hijack without 2FA prompt), `~/.ssh/` keys, cryptocurrency wallet files for major hot-wallet clients (MetaMask, Phantom, Exodus, Electrum, etc.), browser-saved passwords / cookies / autofill (Chrome, Edge, Brave, Firefox profile directories), cloud configuration files (`.aws/credentials`, `gcloud` config, `kube/config`), and shell environment variables that frequently contain API tokens and database URIs. The RAT module opens a WebSocket back to `195.201.194.107` (a Hetzner-range IP) supporting interactive commands: arbitrary shell command execution, file read/write, screenshot capture, simulated input injection, and self-update via fetching new SEA blobs from the Hugging Face repository.

Hugging Face Abuse. The novel element is the abuse of Hugging Face as a malware delivery and update CDN. Hugging Face is allowlisted in many enterprise egress policies because of legitimate ML/AI workloads, and its content-addressable storage backed by Git-LFS provides versioned, high-throughput, TLS-protected delivery. The attackers benefit from: (a) trust inheritance from the platform brand, (b) bypassing URL-reputation-only blocking, (c) free hosting and bandwidth, (d) the ability to push updates by simply git-pushing new SEA blobs to `Lordplay/system-releases`, and (e) plausible deniability — the repo can be styled to look like a legitimate model release. The same pattern was previously observed with the abuse of GitHub Releases, Cloudflare Pages, and Bitbucket; Hugging Face is the next logical evolution.

Attribution. Direct attribution rests on continuity between jpeek895 and prior DPRK npm clusters catalogued by kmsec.uk. The package-naming convention (developer-tool typosquats targeting npm/TypeScript ecosystem users), the multi-account publish-and-prop pattern, the developer-focused exfiltration targets (Telegram for social-engineering pivots, crypto wallets for revenue, cloud credentials for downstream intrusion), and the triple Windows persistence stack all align with the Contagious Interview / Famous Chollima TTP cluster operated by units under the DPRK Reconnaissance General Bureau (RGB) — overlapping with Lazarus subgroup tracking. Attribution confidence: HIGH.

MITRE ATT&CK techniques used in TL-2026-0559

Collection

T1005 Data from Local System; T1113 Screen Capture

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1564 Hide Artifacts

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Credential Access

T1056 Input Capture; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1195 Supply Chain Compromise

Impact

T1531 Account Access Removal

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Affected products and versions in DPRK npm Supply Chain Attack

  • npm registry (OpenJS / GitHub) — terminal-logger-utils
    Vulnerable versions: all published versions
  • npm registry (OpenJS / GitHub) — pretty-logger-utils
    Vulnerable versions: all published versions
  • npm registry (OpenJS / GitHub) — ts-logger-pack
    Vulnerable versions: all published versions
  • npm registry (OpenJS / GitHub) — pinno-loggers
    Vulnerable versions: all published versions
  • Any Node.js developer workstation — Windows, macOS, Linux (OS-dispatched payloads)
    Vulnerable versions: all

Remediation for DPRK npm Supply Chain Attack

Patches

  • Report and remove the malicious packages from the npm registry (npm-security); ensure transitively pinned versions are purged from organization lockfiles.

Immediate actions

  • Remove terminal-logger-utils, pretty-logger-utils, ts-logger-pack, and pinno-loggers from all package.json and lockfiles; rebuild node_modules from a clean cache.
  • Block egress to 195.201.194.107 at perimeter firewalls and EDR network policy.
  • Block or alert on outbound HTTPS to huggingface.co paths matching Lordplay/system-releases and any unknown user/org repo containing executable binary blobs (.exe, .bin, SEA artifacts).
  • Hunt for %LOCALAPPDATA%\MicrosoftSystem64\ directory on all Windows developer endpoints; quarantine and forensicate any host where it exists.
  • Audit HKCU\Software\Microsoft\Windows\CurrentVersion\Run for entries pointing into MicrosoftSystem64 or referencing .vbs launchers in LocalAppData.
  • Audit Windows Scheduled Tasks for unsigned tasks launching binaries from %LOCALAPPDATA%.
  • Rotate all developer credentials potentially exposed: SSH keys, AWS/GCP/Azure tokens, Telegram sessions, browser-saved passwords, cryptocurrency wallet seeds, npm tokens, GitHub PATs.

Workarounds

  • Pin all npm dependencies to known-good versions in package-lock.json / pnpm-lock.yaml and refuse to upgrade until provenance is verifiable.
  • Run `npm install` only inside ephemeral sandboxed containers; never on host developer machines that hold long-lived credentials.

Longer-term hardening

  • Enforce npm postinstall script disablement in CI and on developer workstations (`npm config set ignore-scripts true`) and re-enable only for vetted dependencies.
  • Adopt an internal npm proxy (Verdaccio, JFrog Artifactory, Sonatype Nexus, GitHub Packages) with allowlist-based publisher verification.
  • Deploy EDR with behavioral detection for: postinstall spawning powershell/cmd, postinstall writing to LocalAppData, scheduled-task creation by node.exe, Run-key writes by node.exe.
  • Egress allowlist Hugging Face only for ML/AI workloads; segregate dev workstations from the ML egress profile or require proxy inspection of large LFS pulls.
  • Adopt Sigstore-style cryptographic signing or npm package provenance attestations as a gating policy for production dependencies.

Weaknesses (CWE) in DPRK npm Supply Chain Attack

CWE-506, CWE-829, CWE-494, CWE-1357

Timeline of DPRK npm Supply Chain Attack

  • Hugging Face Hub identified as a new trusted-platform abuse vector for DPRK developer-targeting malware delivery — an evolution beyond prior abuse of GitHub Releases, Bitbucket, and Cloudflare Pages.
  • Campaign confirmed active: malicious packages observed live on the npm registry under the listed accounts; Hugging Face repository Lordplay/system-releases serving SEA binaries; WebSocket C2 195.201.194.107 reachable.
  • Threadlinqs Intelligence publishes TL-2026-0559 with full MITRE ATT&CK mapping, IOC catalogue, and detection coverage for SOC consumption.
  • Attribution to DPRK established via continuity with prior jpeek895 activity previously documented by independent researcher kmsec.uk.
  • Package list (terminal-logger-utils + 3 dependents), npm uploader accounts (jpeek895, jpeek886, pvnd3540749, yggedd817513), C2 IP 195.201.194.107, and Hugging Face repository Lordplay/system-releases publicly catalogued.
  • OX Security publishes research on the terminal-logger-utils campaign; Cyber Security News covers the disclosure, exposing Hugging Face as the second-stage delivery platform.
  • As of 2026-05-29, this DPRK (Famous Chollima/Contagious Interview) npm supply-chain attack remains active: disclosed only days earlier (2026-05-22 OX Security; JFrog 04-23 on the same Lordplay/system-releases repo), with no confirmed takedown of the packages, Hugging Face CDN, or C2 195.201.194.107. The actor is escalating, with 204 malicious npm releases Apr 25-May 25, 2026.

Sources cited for DPRK npm Supply Chain Attack

Detection coverage for TL-2026-0559

As of 2026-05-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0559 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
26 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats