# DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT

> North Korea-linked npm uploader jpeek895 (and three colluding accounts) published terminal-logger-utils plus three dependents (pretty-logger-utils, ts-logger-pack, pinno-loggers) whose postinstall hook executes utils.cjs, an obfuscated multi-stage dropper. utils.cjs fingerprints the host OS, pulls a Node.js Single Executable Application (SEA) from the attacker-controlled Hugging Face repository Lordplay/system-releases, and establishes triple persistence on Windows (%LOCALAPPDATA%\MicrosoftSystem64 + hidden VBS launcher + scheduled task + HKCU\...\Run key). The implant fuses keylogger, infostealer, and RAT functionality — exfiltrating Telegram session data, SSH keys, cryptocurrency wallets, browser credentials, cloud configs, and environment variables — with HTTP keystroke exfil to /api/validate/keyboard-events and a WebSocket C2 at 195.201.194.107 for full interactive machine control. The campaign is a novel TTP evolution: abusing Hugging Face — a trusted AI/ML platform — as both payload-hosting CDN and self-update channel to evade allowlist-based egress controls.

- **Published:** 2026-05-22T12:00:00Z
- **Last reviewed:** 2026-05-22T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0559
- **ID:** TL-2026-0559
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** Contagious Interview (North Korea)
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-05-22, OX Security disclosed an active North Korea-aligned npm supply chain attack centered on the package terminal-logger-utils, uploaded by npm account jpeek895 — an account previously flagged by independent researcher kmsec.uk as part of the DPRK npm-package cluster. Three dependent packages — pretty-logger-utils, ts-logger-pack, pinno-loggers — were published by collaborating accounts jpeek886, pvnd3540749, and yggedd817513 to inflate apparent legitimacy and broaden the install footprint.

Infection Chain. When a developer runs `npm install terminal-logger-utils` (directly or transitively via one of the dependents), npm's `postinstall` lifecycle hook executes the bundled dropper `utils.cjs`. utils.cjs is a heavily obfuscated CommonJS module that performs OS dispatch (Windows / macOS / Linux), then issues an HTTPS request to the Hugging Face Hub repository `Lordplay/system-releases` (a legitimate-looking AI model hosting endpoint) to download an OS-specific Node.js Single Executable Application (SEA) binary. The SEA payload bundles a Node runtime with the malicious JavaScript, eliminating any requirement for a developer-side Node installation and reducing AV/EDR detection of the script body.

Windows Persistence. On Windows hosts the second-stage installs itself to `%LOCALAPPDATA%\MicrosoftSystem64\` — a path chosen to masquerade as a legitimate Microsoft system component. Three persistence mechanisms are established in parallel: (1) a hidden VBScript launcher dropped into the install directory that re-launches the SEA binary on user logon, (2) a Windows Scheduled Task registered under Task Scheduler that re-executes the binary at logon and on a recurring interval, and (3) an `HKCU\Software\Microsoft\Windows\CurrentVersion\Run` registry key as a fallback autostart vector. The triple-redundant persistence is characteristic of DPRK developer-targeting clusters tracked under names such as Contagious Interview / DEV#POPPER / Famous Chollima.

Implant Capabilities. The SEA second-stage is a fused keylogger + infostealer + RAT. Keystroke capture occurs continuously and is exfiltrated over plain HTTP POST to the path `/api/validate/keyboard-events` on attacker infrastructure. Stealer modules target high-value developer artifacts: Telegram `tdata` session folders (allowing full account hijack without 2FA prompt), `~/.ssh/` keys, cryptocurrency wallet files for major hot-wallet clients (MetaMask, Phantom, Exodus, Electrum, etc.), browser-saved passwords / cookies / autofill (Chrome, Edge, Brave, Firefox profile directories), cloud configuration files (`.aws/credentials`, `gcloud` config, `kube/config`), and shell environment variables that frequently contain API tokens and database URIs. The RAT module opens a WebSocket back to `195.201.194.107` (a Hetzner-range IP) supporting interactive commands: arbitrary shell command execution, file read/write, screenshot capture, simulated input injection, and self-update via fetching new SEA blobs from the Hugging Face repository.

Hugging Face Abuse. The novel element is the abuse of Hugging Face as a malware delivery and update CDN. Hugging Face is allowlisted in many enterprise egress policies because of legitimate ML/AI workloads, and its content-addressable storage backed by Git-LFS provides versioned, high-throughput, TLS-protected delivery. The attackers benefit from: (a) trust inheritance from the platform brand, (b) bypassing URL-reputation-only blocking, (c) free hosting and bandwidth, (d) the ability to push updates by simply git-pushing new SEA blobs to `Lordplay/system-releases`, and (e) plausible deniability — the repo can be styled to look like a legitimate model release. The same pattern was previously observed with the abuse of GitHub Releases, Cloudflare Pages, and Bitbucket; Hugging Face is the next logical evolution.

Attribution. Direct attribution rests on continuity between jpeek895 and prior DPRK npm clusters catalogued by kmsec.uk. The package-naming convention (developer-tool typosquats targeting npm/TypeScript ecosystem users), the multi-account publish-and-prop pattern, the developer-focused exfiltration targets (Telegram for social-engineering pivots, crypto wallets for revenue, cloud credentials for downstream intrusion), and the triple Windows persistence stack all align with the Contagious Interview / Famous Chollima TTP cluster operated by units under the DPRK Reconnaissance General Bureau (RGB) — overlapping with Lazarus subgroup tracking. Attribution confidence: HIGH.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1587 Develop Capabilities
- T1585 Establish Accounts
- T1588 Obtain Capabilities
- T1195 Supply Chain Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1547 Boot or Logon Autostart Execution
- T1053 Scheduled Task/Job
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1564 Hide Artifacts
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1056 Input Capture
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1113 Screen Capture
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1095 Non-Application Layer Protocol
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1531 Account Access Removal

## Sources

- [Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack](https://cybersecuritynews.com/hackers-use-hugging-face/)
- [OX Security — research home (primary research source cited by CSN)](https://www.ox.security/)
- [kmsec.uk — DPRK npm package research and jpeek895 prior attribution](https://kmsec.uk/)
- [kmsec.uk DPRK npm packages tracker](https://dprk-research.kmsec.uk/)
- [Node.js Single Executable Applications documentation](https://nodejs.org/api/single-executable-applications.html)
- [MITRE ATT&CK — T1195.002 Compromise Software Supply Chain](https://attack.mitre.org/techniques/T1195/002/)
- [MITRE ATT&CK — T1102 Web Service (legitimate platform abuse)](https://attack.mitre.org/techniques/T1102/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0559
