OAK — OnChain Attack Knowledge

Software · OAK-S29 · malware (npm-package supply-chain malware / first-stage JavaScript loader and infostealer)

OAK-S29 — BeaverTail

Type
malware (npm-package supply-chain malware / first-stage JavaScript loader and infostealer)
Aliases
BeaverTail (the Palo Alto Unit 42 naming established in the canonical July 2023 publication that first publicly documented the family); industry-side cross-attribution labels include the broader campaign naming "Contagious Interview" (Unit 42 campaign-level naming for the recruiter-pretext intrusion set carrying BeaverTail and InvisibleFerret payloads) and "Wagemole" (an adjacent / partially-overlapping campaign naming used by Unit 42 and Mandiant for the DPRK-IT-worker-fraud surface that shares operator cohort and tooling with Contagious Interview); operator-cluster naming overlaps with the broader DPRK Lazarus / TraderTraitor / BlueNoroff intrusion set (CrowdStrike's Famous Chollima naming and Microsoft's Sapphire Sleet / Moonstone Sleet naming for related operator-cohort surfaces).
Active
yes — continuous variants observed through 2024–2025 with sustained npm-registry submission cadence; Unit 42, SentinelOne, ReversingLabs, and Sonatype track ongoing variant-rotation and registry-submission patterns; the principal mitigation surface is npm-registry-side takedown of malicious packages, but operator-side rotation onto new fake-author personas and new package-name surfaces is faster than registry-side takedown response.
First observed
2023-07 (Palo Alto Unit 42 canonical publication date, [unit42beavertail2023]; the underlying campaign activity is attributed back at least into early 2023 by retrospective registry-submission analysis).
Used by Groups
OAK-G01 Lazarus / TraderTraitor cluster and OAK-G08 BlueNoroff / APT38 financial cluster (the family is operationally cross-used across the broader DPRK Lazarus constellation's crypto-industry-targeting surface; the Contagious Interview / Wagemole campaign is attributed to the DPRK constellation at the cluster level rather than to a single sub-cluster, with operator-cohort overlap visible in tradecraft-fingerprint, infrastructure-reuse, and wallet-cluster persistence signatures across the OAK-G01 and OAK-G08 attribution surfaces).
Host platforms
cross-platform (Windows, macOS, Linux — the JavaScript implementation runs natively in the Node.js runtime that the npm-package delivery surface presupposes; this cross-platform property is itself a defining family-architectural feature, distinguishing BeaverTail from the platform-specific macOS-focused TraderTraitor / RustBucket / KandyKorn / SwiftLoader / ObjCShellz lineage at OAK-S08 / S20 / S21 / S22).
Observed Techniques
OAK-T11.001 (third-party signing/custody-vendor compromise, where the BeaverTail-and-InvisibleFerret payload chain delivers initial-access onto a vendor or crypto-firm developer workstation); OAK-T11.002 (wallet-software distribution compromise, where BeaverTail-laden npm packages are themselves the initial-access vector when they reach crypto-firm engineering build environments); pre-incident social-engineering vectors (LinkedIn / Telegram fake-recruiter outreach with "coding test" or "technical interview" pretext payload delivery) sit outside OAK v0.1 on-chain Tactic scope but are the defining entry surface, structurally parallel to the OAK-S08 TraderTraitor lure pattern.

Description

BeaverTail is the JavaScript-based first-stage loader and infostealer family used by the DPRK Lazarus / TraderTraitor / BlueNoroff cluster in the Contagious Interview / Wagemole campaign — a sustained recruiter-pretext intrusion set targeting cryptocurrency-industry engineering staff, blockchain-protocol developers, and DPRK-IT-worker-fraud-adjacent surfaces from at least early 2023 forward. The canonical reference is the Palo Alto Unit 42 publication of July 2023 ([unit42beavertail2023]) which first publicly documented the family, named the Contagious Interview campaign, and established the BeaverTail-as-loader-for-InvisibleFerret-second-stage architecture that defines the family's operational role.

The delivery vector is the principal operational innovation that distinguishes BeaverTail from the broader DPRK-against-crypto-industry intrusion set: where TraderTraitor (OAK-S08) is delivered via direct-download links from operator-controlled domains under fabricated trading-app pretexts, BeaverTail is delivered via malicious npm packages submitted to the public NPM registry under fake author personas with package names mimicking legitimate cryptocurrency-and-blockchain libraries. The operator under a fabricated recruiter persona invites the target to clone a GitHub repository for a "coding test" or "technical interview"; the repository's package.json declares the malicious npm package as a dependency; running npm install retrieves the package from the public registry and executes the BeaverTail payload during the postinstall script lifecycle. This vector exploits the implicit trust developers extend to package-manager-installed dependencies and the structural asymmetry between npm-registry-side malicious-package detection (slow, after-the-fact takedown) and operator-side malicious-package submission (fast, low-cost, under-rotated-fake-author-persona).

Post-execution behaviour is staged: BeaverTail performs reconnaissance on the host (operating system, installed software, browser presence), harvests browser-stored credentials, browser-stored cryptocurrency-wallet extension data (MetaMask, Phantom, and similar), and other developer-relevant credential stores (SSH keys, AWS / GCP credential files, .env files in common project directories), and stages the InvisibleFerret Python second-stage backdoor (OAK-S30) for persistent access and continued exfiltration. The two-stage architecture mirrors the broader DPRK intrusion-set design pattern (lightweight first-stage reconnaissance and credential-theft followed by heavier second-stage backdoor) seen also in the TraderTraitor → RustBucket / KandyKorn / SwiftLoader chains.

The family's role in the OAK-G01 / OAK-G08 monetization chain is the initial-access node into the crypto-industry developer-workstation perimeter; downstream movement into wallet-extension-protected key material, cloud-credential-protected infrastructure, and in some cases into vendor-side signing infrastructure feeds the canonical OAK-G01 / OAK-G08 supply-chain-compromise extraction pattern documented across multiple major incidents 2023–2025. From a defender perspective the family is the npm-registry-side parallel of the LinkedIn-and-Telegram-side TraderTraitor pattern — same operator cohort, same downstream extraction Tactics, structurally different entry surface.

Observed examples

  • Unit 42 canonical July 2023 publication ([unit42beavertail2023]). Multiple-package campaign cohort documented across approximately ten malicious npm packages submitted under fake author personas mimicking legitimate cryptocurrency-developer-tooling brands; the publication established the BeaverTail naming and the Contagious Interview campaign naming. Confirmed-grade attribution to DPRK at the cluster level.
  • Continuous npm-registry submission cadence (2023–2025). Unit 42, SentinelOne, ReversingLabs, Sonatype, and Phylum tracked sustained malicious-package-submission cadence through 2024–2025 with operator-side rotation onto new fake-author personas and new package-name surfaces as fast as registry-side takedown response could close older surfaces. Aggregate submission counts in the hundreds of malicious packages with operator-cohort-attribution to the DPRK Contagious Interview / Wagemole campaign.
  • Wagemole / DPRK-IT-worker-fraud surface convergence. The Wagemole campaign — DPRK operatives obtaining remote-software-engineer employment at U.S. and Western firms under fabricated identities to siphon salary income for the DPRK regime — uses BeaverTail-and-InvisibleFerret tooling on attacker-side and target-side of the same operator-cohort infrastructure; the convergence between the two campaigns is documented in CrowdStrike's Famous Chollima reporting and in U.S. DOJ indictments of facilitators in the broader DPRK-IT-worker-fraud scheme.
  • Multiple per-incident crypto-industry compromises (2023–2025). The BeaverTail-and-InvisibleFerret entry vector has been the documented or strongly-inferred initial-access surface for multiple per-incident crypto-industry compromises through 2024–2025 — Mandiant, SentinelOne, and Unit 42 attribute clusters of incidents to the campaign without per-incident published post-mortems in many cases. Inferred-strong attribution per industry-forensic source.
  • OAK on-chain example surface. No OAK examples/ entry exists for BeaverTail-binary specifically as of v0.1; the OAK angle is the OAK-G01 / OAK-G08 cluster ransom-and-theft proceeds laundering tail rather than per-package-deployment incidents.

Detection / attribution signals

Defenders should treat BeaverTail-family detection as a multi-surface problem because the family rotates package-name surfaces and fake-author personas faster than any single static-detection-rule set can keep pace with:

  • npm-registry-side telemetry (the highest-yield top-of-funnel signal) — anomalous package submission patterns under newly-created npm accounts; package names mimicking legitimate cryptocurrency-and-blockchain libraries with subtle typo-squat or namespace-confusion variations; postinstall scripts performing network egress to operator-controlled C2 infrastructure during package-installation; package code shape inconsistent with stated package-purpose. ReversingLabs, Sonatype, Phylum, Snyk, and GitHub Dependabot all maintain malicious-package-detection rule sets covering the BeaverTail-family signatures; consume current rules from these vendors rather than transcribing static IOCs.
  • GitHub-side telemetry — newly-created GitHub repositories with "coding test" / "technical interview" / "blockchain dev assignment" framing; minimal commit history and operator-controlled author identity; package.json declaring suspicious npm package as dependency; README content mimicking legitimate technical-interview pretext. CrowdStrike's Famous Chollima reporting documents the operator-side GitHub repository creation pattern.
  • Endpoint-side process-tree fingerprintsnpm install parent process spawning child processes performing reconnaissance, credential-store harvesting, and network egress to C2 infrastructure during the postinstall script lifecycle; cross-platform behaviour (Windows / macOS / Linux Node.js runtime).
  • C2-domain naming patterns — domains mimicking crypto-firm careers / recruiting / portfolio / coding-test brands; current IOCs published in Unit 42 reporting and in continuous CTI-vendor feeds (consume via threat-intel platforms rather than transcribe).
  • Lure-channel telemetry — anomalous LinkedIn / Telegram recruiter outreach to engineering staff with subsequent GitHub-repository link delivery; this is the highest-yield top-of-funnel signal and is the surface CrowdStrike, Mandiant, and Unit 42 specifically call out as the campaign's distinguishing tradecraft fingerprint relative to TraderTraitor's direct-download-link delivery.
  • Cross-correlation with downstream InvisibleFerret signatures (OAK-S30) — the BeaverTail-to-InvisibleFerret payload chain is sufficiently consistent across the campaign that detection of either family raises the prior on the other's presence; see OAK-S30 for the second-stage backdoor's distinct detection surface.
  • CTI vendor coverage — Palo Alto Unit 42 (canonical July 2023 publication and continuous tracking; [unit42beavertail2023]), SentinelOne (sustained npm-supply-chain reporting), ReversingLabs (npm-registry-side malicious-package detection), Sonatype (registry-side detection and takedown coordination), Phylum (npm-and-PyPI supply-chain attack reporting), CrowdStrike (Famous Chollima cluster naming and continuous tracking), Mandiant (Wagemole-and-Contagious-Interview convergence reporting), Microsoft Threat Intelligence (Sapphire Sleet / Moonstone Sleet related-cluster naming).

Note: omit specific file hashes from this entry. Defenders should consume current IOCs from Unit 42's published indicator list and from the live CTI-vendor feeds named above; specific package names and fake-author personas rotate faster than any static IOC list.

Citations

  • [unit42beavertail2023] — Palo Alto Unit 42, "Hacking Employers and Seeking Employment: DPRK Threat Actors Use Contagious Interview Campaign," July 2023; canonical publication establishing the BeaverTail naming and the Contagious Interview campaign naming. (NEW citation — see summary.)
  • [unit42contagiousinterview2024] — Palo Alto Unit 42 follow-up reporting on Contagious Interview campaign evolution and BeaverTail variant rotation through 2024. (NEW citation — see summary.)
  • [mandiantwagemole2024] — Mandiant Wagemole-and-Contagious-Interview campaign convergence reporting and DPRK-IT-worker-fraud surface analysis. (NEW citation — see summary.)
  • [crowdstrikefamouschollima2024] — CrowdStrike Famous Chollima cluster naming and operator-cohort-tracking documentation. (NEW citation — see summary.)
  • [sentineloneBeaverTail2024] — SentinelOne BeaverTail / InvisibleFerret continuous tracking and macOS-variant analysis. (NEW citation — see summary.)
  • [reversinglabsBeaverTail2024] — ReversingLabs npm-supply-chain attack reporting on BeaverTail-family malicious-package submissions. (NEW citation — see summary.)
  • [chainalysis2024dprk] — DPRK-attributed cryptocurrency-theft and ransom-proceeds aggregate context (also cited in OAK-G01, OAK-S08, OAK-S25).

Discussion

On lineage. BeaverTail sits within the broader DPRK Lazarus / TraderTraitor / BlueNoroff cluster's trojanized-developer-tooling lineage but operates on a structurally distinct delivery surface from the macOS-focused TraderTraitor / RustBucket / KandyKorn / SwiftLoader / ObjCShellz lineage at OAK-S08 / S20 / S21 / S22. Where the macOS lineage targets engineering-staff workstations through direct-download-link delivery of trojanized trading-app binaries, BeaverTail targets the same population through npm-registry-side supply-chain compromise — the same operator cohort exploiting a different trust surface. The lineage convergence is at the operator-cohort level rather than the codebase or platform level; treating BeaverTail as a TraderTraitor-derivative would mis-frame the structural distinctness of the npm-supply-chain delivery vector.

On the BeaverTail / InvisibleFerret two-stage architecture. The BeaverTail-as-first-stage-loader and InvisibleFerret-as-second-stage-backdoor design pattern is one of the canonical DPRK two-stage intrusion architectures, structurally parallel to the TraderTraitor → RustBucket / KandyKorn / SwiftLoader chains documented in OAK-S08 / S20 / S21 / S22. The two-stage design produces several operational advantages: lightweight first-stage payload is harder to detect at the npm-registry-side static-analysis layer; reconnaissance-and-triage step at first-stage allows operator-side selection of which compromises to escalate to second-stage backdoor deployment; second-stage codebase rotation independent of first-stage delivery surface allows persistence-tooling refresh without losing the established npm-registry-side delivery pipeline.

On the npm-supply-chain attack surface as a strategic surface. The Contagious Interview campaign is one of the highest-volume DPRK-attributable supply-chain attack campaigns on the public record and represents a sustained operator-cohort investment in the npm-registry-side attack surface specifically. The strategic asymmetry favours operators: registry-side malicious-package detection-and-takedown is slower than operator-side fake-author-persona-and-package-name rotation; the developer-workstation-trust-surface that npm-package-installation presupposes is structurally hard to harden without imposing material friction on the legitimate-developer experience. From a defender perspective the family is the canonical worked example for the malicious-npm-package as initial-access vector against crypto-industry developer-staff threat model; defenders writing supply-chain-attack control programs should treat the family and the broader Contagious Interview campaign as the principal evidence base for that threat model's empirical reality.

On ecosystem position. BeaverTail is the initial-access node in one branch of the DPRK financial-funding chain; the InvisibleFerret second-stage and downstream OAK-G01 / OAK-G08-attributed extraction Techniques (T10.001, T11.001, T11.002, T11.003) and OAK-T7-Tactic laundering complete the chain. A defender control program targeting BeaverTail at the npm-supply-chain layer compounds with on-chain G01 / G08 cluster watchlists at the off-ramp layer; either alone is partial coverage.

Techniques observed (2)

Used by