s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-py.pylangghost

📛 Threat Title

Malware family: PylangGhost

Category: PylangGhost First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `py.pylangghost`. Printable name: PylangGhost. Aliases: ICEBITE.PYTHON,WeaselStore.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain py.pylangghost

IOC database

Type
domain
Value
py.pylangghost
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-py.pylangghost

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

Remediations (10)

  • web:any.run

    Discover analysis of PyLangGhost RAT, the newest Lazarus Group malware targeting finance and tech professionals.

  • web:anyrun.substack.com

    Unlike common malware that spreads through pirated software or infected USB drives, PyLangGhost RAT is delivered via highly targeted social engineering campaigns aimed at the technology, finance, and crypto industries, with developers and executives as prime victims. In these attacks, adversaries stage fake job interviews and trick their targets into believing that their browser is blocking ...

  • web:cyberpress.org

    Although the researcher did not kmsec pursue deep reverse engineering after confirming the malware family as DPRK-linked PylangGhost , the findings remain important. They show how attackers can hide a remote access trojan inside npm packages that appear developer-related and routine.

  • web:cybersecuritynews.com

    A remote access trojan known as PylangGhost has appeared on the npm registry for the first time, concealed inside two malicious JavaScript packages. The malware , first publicly disclosed by Cisco Talos in June 2025 and attributed to the North Korean state-sponsored threat group FAMOUS CHOLLIMA, marks a significant escalation in software supply chain attacks targeting developers around the ...

  • web:cyberwebspider.com

    These packages, appearing in late February and early March 2026, respectively, contained the PylangGhost loader within key JavaScript files. Technical Details of the Attack The malware's campaign identifier, "ML2J," and its command-and-control infrastructure, using the domain malicanbur [.]pro, highlight its sophistication.

  • web:encyb.com

    EXECUTIVE SUMMARY A software supply chain campaign has been identified distributing the PylangGhost Remote Access Trojan (RAT) through malicious npm packages targeting developers and software development environments. The attackers initially publish legitimate package versions to build trust and later introduce obfuscated malicious code in subsequent updates to evade detection.

  • web:gbhackers.com

    Malicious npm packages are delivering the North Korean-linked PylangGhost remote access trojan (RAT) in a new software supply chain campaign.

  • web:malpedia.caad.fkie.fraunhofer.de

    First instance of PylangGhost RAT observed on npm PylangGhost 2026-03-11 ⋅ Microsoft ⋅ Microsoft Defender Experts, Microsoft Defender Security Research Team Contagious Interview: Malware delivered through fake developer job interviews BeaverTail OtterCookie StoatWaffle InvisibleFerret PylangGhost GolangGhost Contagious Interview

  • web:news.backbox.org

    Unlike common malware that spreads through pirated software or infected USB drives, PyLangGhost RAT is delivered via highly targeted social engineering campaigns aimed at the technology, finance, and crypto industries, with developers and executives as prime victims.

  • web:vpncentral.com

    A new software supply chain campaign has pushed the PylangGhost remote access trojan through malicious npm packages, expanding a malware family previously tied to North Korean threat activity into one of the world's most widely used developer ecosystems. Security researchers say the packages react-refresh-update and @jaime9008/math-service carried an obfuscated JavaScript loader that fetched ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.