Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Use 35 NPM package to spread the new wave of ‘fake interview’
    Security

    Use 35 NPM package to spread the new wave of ‘fake interview’

    PineapplesUpdateBy PineapplesUpdateJune 25, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Use 35 NPM package to spread the new wave of ‘fake interview’
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Use 35 NPM package to spread the new wave of ‘fake interview’

    A new wave of North Korea’s ‘infectious interview’ campaign is targeted by job seekers with evil NPM packages that infect Dev’s equipment with Infosellers and Backdore.

    Packages were discovered Socket threat researchThose who report that they load the two-well-recorded payloads associated with the Beertel Information-Stellar and Invitating Backdor, DPRK actors on the machines of the victims.

    The latest attack wave uses 35 malicious packages presented to NPM through 24 accounts. The packages have been downloaded more than 4,000 times in total, and six of them are available at the time of writing.

    Many of the 35 malicious NPM packages mimic typosquat or mimic to mimic famous and reliable libraries, making them particularly dangerous.

    The remarkable examples of them are:

    • React-Plade-SDK, Reactbutstrapes
    • Vite-plugin-next-Refresh, Vite-LODER-SVG
    • Node-mongoz
    • jsonpacks, jsonspecific
    • Chalk kaf
    • Node Loggors, *-Kalger
    • Framar-Motion-Apt
    • Nextjs-inight
    • Structure-logger, logbin-nod

    The victims, usually software engineers and developers, are led by North Korean operatives to download these packages, which are presented as recruitments, who request job candidates to work on a test project.

    “As a recruiter on LinkedIn, North Korean dangers send” assignments “to the developers and job seekers through the North Korean threat actor Google Docs, embedding these malicious packages within the project, and often pressurizing candidates to run code while screen-sharing.”

    Fodder document
    Documents sent for target
    Source: socket

    The assignment is hosted on the bitbacket and disguised as legitimate tests, but in fact, they trigger a transition chain that drops several payloads on the target computer.

    The first stage is the hexwell loader, which is hidden in NPM packages, which fingerprints the host, contacts the actor’s command-end-control (C2) server, and uses ‘eval ()’ to bring and perform the second phase payload, bearrtel.

    Beertel is a multi-platform information-steller and malware loader, stealing browser data, including cookies and cryptocurrency wallets, and loads the third stage, invisible.

    The invisible is a cross-platform consistent backdor that is given as a zip file, providing the attackers to the afflicted system with deep, remote control, file theft and screen-performance capabilities.

    Finally, the attackers release a cross-platform (Windows, MacoS, Linux) Keyloxon tools that hook in low-level input events and make real-time monitoring and data exfoliation.

    This kelogger was only associated with one of the NPM surnames used in the campaign, so it can only be deployed on selected high-value goals.

    Overview of attack
    Overview of attack
    Source: socket

    Software developers contacted with attractive remote job offers should treat these invitations carefully and always run unknown code in containers or virtual machines instead of executing it on their OS.

    Last March, North Korean hackers Lazarus were caught presenting another set of malicious packages on NPM, so it is an ongoing risk.


    Tines needle

    Patching meant complex scripts, long and endless fire drills. No more.

    In this new guide, the tines break down how it is leveling with modern organ automation. Patch fast, reduce overhead, and focus on strategic tasks – no complex script is required.

    fake interview NPM package spread Wave
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThese underraged AI devices are independent – and you probably don’t even know about them
    Next Article Bumble is cutting about one -third of its global staff
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    I’ve tried almost every Linux package manager – these remain my favorites

    December 16, 2025
    AI/ML

    PayPal’s agentic commerce play shows that flexibility, not standards, will define the next e-commerce wave

    October 28, 2025
    Security

    Your Uber driver has a new endeavor: training an AI for cash

    October 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.