BeaverTail (Javascript)
- Malware type
- loader, spyware, trojan
- Family
- Malware family
- Profile updated
- 2026-07-07 13:14:54
Targeted industries: financial-services technology-and-telecommunications
Context
BeaverTail is a JavaScript malware primarily distributed through NPM packages. It is designed for information theft and to load further stages of malware, specifically a multi-stage Python-based backdoor known as InvisibleFerret. BeaverTail targets cryptocurrency wallets and credit card information stored in the victim's web browsers. Its code is heavily obfuscated to evade detection. Threat actors can either upload malicious NPM packages containing BeaverTail to GitHub or inject BeaverTail code into legitimate NPM projects. Researchers have identified additional Windows and macOS variants, indicating that the BeaverTail malware family is likely still under development.
Reports & references
- Palo Alto Unit 42 — Two Campaigns By North Korea Bad Actors Target Job Hunters (report)
- Palo Alto Unit 42 — Fake North Korean It Worker Activity Cluster (report)
- Trend Micro — Russian Infrastructure North Korean Cybercrime (report)
- zscaler.com — Pyongyang Your Payroll Rise North Korean Remote Workers West (report)
- about.gitlab.com — Gitlab Threat Intelligence Reveals North Korean Tradecraft (report)
- Microsoft — Contagious Interview Malware Delivered Through Fake Developer Job Interviews (report)
- securitylabs.datadoghq.com — Tenacious Pungsan Dprk Threat Actor Contagious Interview (report)
- esentire.com — Bored Beavertail Invisibleferret Yacht Club A Lazarus Lure Pt 2 (report)
- recordedfuture.com — Inside The Scam North Koreas It Worker Threat (report)
- securonix.com — Analysis Of Devpopper New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors (report)
- ESET — Deceptivedevelopment Targets Freelance Developers (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Beavertail (report)
- abstract.security — Contagious Interview Evolution Of Vscode And Cursor Tasks Infection Chains (report)
- socket.dev — North Korean Apt Lazarus Targets Developers With Malicious Npm Package (report)
- nimanthadeshappriya.com — From Colombo To Pyongyang (report)
- blog.nviso.eu — Contagious Interview Actors Now Utilize Json Storage Services For Malware Delivery (report)
- www-cdn.anthropic.com — B2A76C6F6992465C09A6F2Fce282F6C0Cea8C200 (report)
- jp.security.ntt — Contagious Interview Ottercookie (report)
- ESET — Deceptivedevelopment From Primitive Crypto Theft To Sophisticated Ai Based Deception (report)
- doi.org — Arxiv.2505.21725 (report)
- radar.securityalliance.org — Vs Code Tasks Abuse By Contagious Interview Dprk (report)
- asec.ahnlab.com — 87299 (report)
- gitlab-com.gitlab.io — North Korean Malware Sept 2025 (report)
- stacklok.com — Dependency Hijacking Dissecting North Koreas New Wave Of Defi Themed Open Source Attacks Targeting Developers (report)
- redasgard.com — Hunting Lazarus Contagious Interview C2 Infrastructure (report)