ATT&CKReferencesSocket Contagious Interview NPM April 2025

Socket Contagious Interview NPM April 2025

Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupContagious Interview

Contagious Interview has used hexadecimal string encoding to hide critical JavaScript module names, function names, and C2 URLs, which are decoded dynamically at runtime.

T1027.013
Encrypted/Encoded File
MalwareHexEval Loader

HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1036.005
Match Legitimate Resource Name or Location
MalwareHexEval Loader

HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects.

T1041
Exfiltration Over C2 Channel
MalwareHexEval Loader

HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1041
Exfiltration Over C2 Channel
GroupContagious Interview

Contagious Interview has exfiltrated data from a compromised host to actor-controlled C2 servers.

T1059.007
JavaScript
MalwareHexEval Loader

HexEval Loader has executed malicious JavaScript code.

T1071.001
Web Protocols
MalwareHexEval Loader

HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2.

T1105
Ingress Tool Transfer
MalwareHexEval Loader

HexEval Loader has been used to download a malicious payload to include BeaverTail.

T1140
Deobfuscate/Decode Files or Information
MalwareHexEval Loader

HexEval Loader has decoded its payload prior to execution.

T1204.005
Malicious Library
GroupContagious Interview

Contagious Interview has relied on users to install a malicious library from a code repository to infect the victim's device and has led to additional payload distribution and theft of sensitive data.

T1571
Non-Standard Port
GroupContagious Interview

Contagious Interview has used TCP port 1224 for C2.

T1583.001
Domains
GroupContagious Interview

Contagious Interview has registered domains to leverage in their social engineering campaigns. Contagious Interview has also registered domains to utilize for C2.

T1583.006
Web Services
GroupContagious Interview

Contagious Interview has used web services such as Dropbox to receive stolen data and Google Drive, Firebase, GitHub, and Telegram to disseminate files. Contagious Interview has also used a cloud platform such as Vercel for C2 operations leveraging malicious web applications and static pages. Contagious Interview has also used Slack to coordinate their activities.

T1585
Establish Accounts
GroupContagious Interview

Contagious Interview has created and maintained personas on code repositories to distribute malicious payloads.

T1587
Develop Capabilities
GroupContagious Interview

Contagious Interview developed malicious NPM packages for delivery to or retrieval by victims.

T1608.001
Upload Malware
GroupContagious Interview

Contagious Interview has hosted malicious payloads on code repositories used as lures for victims to download.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.