npm install -dprk: DeceptiveDevelopment’s Supply-Chain Playbooks Against Developers - Cybersecurity Conference

npm install –dprk: DeceptiveDevelopment’s Supply-Chain Playbooks Against Developers

DPRK-linked DeceptiveDevelopment continues to compromise software developers by abusing the trust built into modern development workflows.

Based on multiple investigations and data retrieved from our telemetry, this talk examines the group’s recent evolution around malicious npm packages and its expansion into other developer ecosystems, including PyPI and Go. It focuses on how routine actions such as installing dependencies, opening coding challenges, or working inside a repository can become the first step of a multi-stage compromise. We will break down observed chains where malicious packages execute code during installation, fingerprint the host, retrieve remote payloads from public dead drops, abuse transitive dependencies, and route staging through a combination of legitimate services, self-hosted infrastructure such as Git repositories, and decentralized storage networks (like IPFS).

The talk will also examine the group’s evolving use of blockchain infrastructure for payload and C2 retrieval, covering techniques such as EtherHiding and NullReceiver alongside previously observed TRON and Aptos activity. We will also demonstrate how targeted hunting across publicly accessible Google Docs can uncover related repositories, infrastructure, and campaign activity.

The talk will cover notable malware behaviors embedded in or delivered through these packages, including SSH key backdooring, OpenClaw configuration theft, and the deployment of BeaverTail, OtterCookie, InvisibleFerret, WeaselStore, and OmniStealer, with a more in-depth breakdown of its use of Telegram as a backup exfiltration channel.

By combining social engineering, package ecosystem abuse, trusted and self-hosted infrastructure, blockchain-based resource retrieval, and developer-tool automation, DeceptiveDevelopment is building increasingly resilient initial-access chains while keeping individual packages and repositories lightweight, disposable, and easy to re-stage.

Attendees will leave with a technical understanding of the actor’s recent innovations across the software supply-chain layer, along with practical suggestions to pivot and hunt across repositories, package metadata, dependency graphs, endpoints, public documents, network telemetry, and blockchain activity.

Ettore Bordoni – ESET

Ettore Bordoni is a Malware Researcher at ESET, where he works on threat actor tracking, malware analysis, and emerging intrusion tradecraft, with a focus on East Asian operators. His background spans reverse engineering, incident response, detection engineering, and threat intelligence, with an emphasis on translating technical research into practical threat hunting, detection opportunities, and defensive guidance.