DPRK npm packages
The finest (and largest?) collection of malicious npm packages attributed to North Korea on the internet.
These npm packages facilitate FAMOUS CHOLLIMA's Contagious Interview campaign. FAMOUS CHOLLIMA is a threat actor assessed to be directed by the Democratic People's Repubic of Korea (DPRK, North Korea).
Want data from a specific time period? Manipulate the UNIX timestamp (in ms) in the start and end parameters of the URL.
Want json? GET json by appending a json URL parameter.
Showing 170 malicious npm releases from 128 distinct packages distributed between 2025-10-27 and 2025-11-26
About this collection
FAMOUS CHOLLIMA has been facilitating the Contagious Interview campaign by deploying npm packages to the npm registry as early as August 2024. I have been actively tracking FAMOUS CHOLLIMA’s package distributions since ~February 2025 and in July 2025 I opened the collection to the public.
Every package and version listed here has been manually attributed to FAMOUS CHOLLIMA with high confidence based on the characteristics of the alleged maintainer, the package contents, the indicators, and the malware behaviour (if I’ve made a mistake, please contact me below).
The IOCs represent only the earliest stages of an infection chain. Typically these packages are designed to execute remote content that facilitates further infection (i.e. OtterCookie, BEAVERTAIL, et. al.) and involve more indicators than are visible here.
This collection is not an exhaustive list. Packages slip through my hunting and attribution process. Other researchers have discovered some too, but I believe this is the largest open collection of Contagious Interview npm packages on the internet.
Time permitting, I intend to share some technical details of my tracking and some notable findings (I really should update my blog). In the meantime, I recommend socket.dev’s series of posts on the campaign. They have done a really great job of reporting on the campaign in detail:
- January 2025 - North Korean APT Lazarus Targets Developers with Malicious npm Package
- March 2025 - Lazarus Strikes npm Again with New Wave of Malicious Packages
- April 2025 - Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads
- June 2025 - Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages
- October 2025 - North Korea’s Contagious Interview Campaign Escalates: 338 Malicious npm Packages, 50,000 Downloads - Thanks for the credit!
Want to get in touch? Contact dprk-research[@]pm[.]me.