Datadog Security Labs · Crawled Jul 25, 2026

Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview | Datadog Security Labs

4 IoCs 2 Malware
Read original article ↗

AI Summary

In September 2024, Datadog Security Research identified three malicious npm packages—passports-js, bcrypts-js, and blockscan-api—linked to the DPRK-associated threat actor 'Tenacious Pungsan'. These packages distributed BeaverTail, a JavaScript infostealer and downloader used in the Contagious Interview campaign targeting US tech job-seekers. The malware steals cryptocurrency wallet data, browser credentials, and deploys a second-stage Python backdoor called InvisibleFerret. The activity is tied to known infrastructure and overlaps with prior Contagious Interview TTPs, indicating ongoing targeting of developers.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 4 extracted

Type Value Detail
Package passports-js Details →
Package bcrypts-js Details →
Package blockscan-api Details →
IP 95[.]164[.]17[.]24 Details →

MITRE ATT&CK TTPs 20 techniques