Datadog Security Labs · Crawled Jul 25, 2026
Stressed Pungsan: DPRK-aligned threat actor leverages npm for initial access | Datadog Security Labs
8 IoCs 1 Actors
Read original article ↗
AI Summary
Stressed Pungsan, a DPRK-aligned threat actor, has been observed leveraging malicious npm packages for initial access. The actor published two packages, 'harthat-hash' and 'harthat-api', which execute a preinstall script to download and run a malicious DLL from a C2 server. The infrastructure and TTPs align with Microsoft's MOONSTONE SLEET, indicating a focus on Windows environments and potential espionage or credential theft objectives.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 8 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 142[.]111[.]77[.]196 | Details → |
| Package | harthat-hash | Details → |
| Package | harthat-api | Details → |
| Filename | Temp.b | Details → |
| Filename | package.db | Details → |
| Filename | package.bat | Details → |
| SHA-256 | d2a74db6b9c900ad29a81432af72eee8ed4e22bf61055e7e8f7a5f1a33778277 | Details → |
| Registry User | nagasiren978 | Details → |
MITRE ATT&CK TTPs 10 techniques
T1027 Obfuscated Files or Information · Defense Evasion T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1085 T1085 T1134 Access Token Manipulation · Defense Evasion T1204.002 Malicious File · Execution T1218.011 Rundll32 · Defense Evasion T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1566.001 Spearphishing Attachment · Initial Access