TF-MAL-py.pylangghost
📛 Threat Title
Malware family: PylangGhost
Description
ThreatFox malware family `py.pylangghost`. Printable name: PylangGhost. Aliases: ICEBITE.PYTHON,WeaselStore.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
py.pylangghost
IOC database
- Type
- domain
- Value
py.pylangghost- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-py.pylangghost
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:any.run
Discover analysis of PyLangGhost RAT, the newest Lazarus Group malware targeting finance and tech professionals.
-
web:anyrun.substack.com
Unlike common malware that spreads through pirated software or infected USB drives, PyLangGhost RAT is delivered via highly targeted social engineering campaigns aimed at the technology, finance, and crypto industries, with developers and executives as prime victims. In these attacks, adversaries stage fake job interviews and trick their targets into believing that their browser is blocking ...
-
web:cyberpress.org
Although the researcher did not kmsec pursue deep reverse engineering after confirming the malware family as DPRK-linked PylangGhost , the findings remain important. They show how attackers can hide a remote access trojan inside npm packages that appear developer-related and routine.
-
web:cybersecuritynews.com
A remote access trojan known as PylangGhost has appeared on the npm registry for the first time, concealed inside two malicious JavaScript packages. The malware , first publicly disclosed by Cisco Talos in June 2025 and attributed to the North Korean state-sponsored threat group FAMOUS CHOLLIMA, marks a significant escalation in software supply chain attacks targeting developers around the ...
-
web:cyberwebspider.com
These packages, appearing in late February and early March 2026, respectively, contained the PylangGhost loader within key JavaScript files. Technical Details of the Attack The malware's campaign identifier, "ML2J," and its command-and-control infrastructure, using the domain malicanbur [.]pro, highlight its sophistication.
-
web:encyb.com
EXECUTIVE SUMMARY A software supply chain campaign has been identified distributing the PylangGhost Remote Access Trojan (RAT) through malicious npm packages targeting developers and software development environments. The attackers initially publish legitimate package versions to build trust and later introduce obfuscated malicious code in subsequent updates to evade detection.
-
web:gbhackers.com
Malicious npm packages are delivering the North Korean-linked PylangGhost remote access trojan (RAT) in a new software supply chain campaign.
-
web:malpedia.caad.fkie.fraunhofer.de
First instance of PylangGhost RAT observed on npm PylangGhost 2026-03-11 ⋅ Microsoft ⋅ Microsoft Defender Experts, Microsoft Defender Security Research Team Contagious Interview: Malware delivered through fake developer job interviews BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview
-
web:news.backbox.org
Unlike common malware that spreads through pirated software or infected USB drives, PyLangGhost RAT is delivered via highly targeted social engineering campaigns aimed at the technology, finance, and crypto industries, with developers and executives as prime victims.
-
web:vpncentral.com
A new software supply chain campaign has pushed the PylangGhost remote access trojan through malicious npm packages, expanding a malware family previously tied to North Korean threat activity into one of the world's most widely used developer ecosystems. Security researchers say the packages react-refresh-update and @jaime9008/math-service carried an obfuscated JavaScript loader that fetched ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.