GitHub warns of social engineering campaign targeting tech employees via npm
GitHub has disclosed a low-volume social engineering campaign aimed at the personal accounts of employees at technology companies. The attack combines fraudulent repository invitations with malicious npm dependencies to deliver malware. None of GitHub's or npm's own systems were compromised, but the company has suspended associated accounts and is sharing indicators so targets can identify and remediate exposure.
Who is behind the campaign
GitHub assesses with high confidence that the campaign is the work of a group aligned with North Korean objectives, known separately as Jade Sleet (Microsoft Threat Intelligence) and TraderTraitor (CISA). The group typically focuses on individuals tied to cryptocurrency and blockchain organizations, though it also goes after vendors who serve those firms. Some targets in this campaign were associated with the cybersecurity sector as well.
How the attack works
The attack chain relies on social engineering to convince a victim to run code from a repository. GitHub has observed three main steps:
- The actor creates fake personas — or takes over legitimate accounts — on platforms including LinkedIn, Slack, and Telegram. Contact may start on one platform and then shift to another before any malicious content is shared.
- The target is invited to collaborate on a public or private GitHub repository and is persuaded to clone and execute its contents. Repository themes include media players and cryptocurrency trading tools. The malicious code is delivered via npm dependencies that the actor publishes only at the time the invitation is sent, limiting the window for scrutiny.
- The malicious npm package acts as first-stage malware, fetching and executing second-stage payloads on the victim's machine from the domains listed below.
In some cases, the actor skips the repository step entirely and delivers the malicious software directly through messaging or file-sharing platforms. GitHub notes that Phylum Security published an independent analysis of the first-stage malware's behavior.
What GitHub has done
GitHub has suspended the npm and GitHub accounts tied to the campaign, published the indicators below, and filed abuse reports with domain hosts where the domains were still active at the time of detection.
Recommended actions for targets
Anyone who was solicited to clone or download content from one of the flagged accounts should consider themselves a target of the campaign. GitHub recommends:
- Reviewing the security log for
action:repo.add_memberevents to see whether a repository invitation from one of the listed accounts was accepted. - Treating social media requests to collaborate on or install npm packages with suspicion, particularly for those working in the targeted sectors.
- Examining dependencies and install scripts carefully. Net-new or very recently published packages, as well as scripts and dependencies that make network connections during installation, warrant extra scrutiny.
- Contacting an employer's cybersecurity team if targeted.
- Resetting or wiping potentially affected devices and rotating passwords and stored credentials if any content from the campaign was executed.
Indicators of compromise
Domains
npmjscloud[.]com
npmrepos[.]com
cryptopriceoffer[.]com
tradingprice[.]net
npmjsregister[.]com
bi2price[.]com
npmaudit[.]com
coingeckoprice[.]com
Malicious npm packages
assets-graph
assets-table
audit-ejs
audit-vue
binance-prices
coingecko-prices
btc-web3
cache-react
cache-vue
chart-tablejs
chart-vxe
couchcache-audit
ejs-audit
elliptic-helper
elliptic-parser
eth-api-node
jpeg-metadata
other-web3
price-fetch
price-record
snykaudit-helper
sync-http-api
sync-https-api
tslib-react
tslib-util
ttf-metadata
vue-audit
vue-gws
vuewjs
Malicious GitHub accounts
GalaxyStarTeam
Cryptowares
Cryptoinnowise
netgolden
Malicious npm accounts
charlestom2023
eflodzumibreathbn
galaxystardev
garik.khasmatulin.76
hydsapprokoennl
leimudkegoraie3
leshakov-mikhail
linglidekili9g
mashulya.bakhromkina
mayvilkushiot
outmentsurehauw3
paupadanberk
pormokaiprevdz
podomarev.goga
teticseidiff51
toimanswotsuphous
ufbejishisol



