Executive Summary
In late 2025, security researchers from NVISO identified a new supply chain attack campaign attributed to North Korean threat actors, leveraging popular JSON storage services—such as JSON Keeper, JSONsilo, and npoint.io—to covertly distribute trojanized malware payloads. The attackers embedded malicious code in legitimate-looking coding projects and lured developers, weaponizing widely used file formats and cloud APIs as their delivery mechanism. Consequently, targeted organizations experienced risks of credential theft, data exfiltration, and potential network breaches, with increased threat visibility due to attackers’ creative use of benign infrastructure as covert command and control channels.
This incident highlights a broader trend: state-sponsored actors are rapidly innovating malware delivery by abusing cloud-based, trusted SaaS platforms. The use of developer-centric resources and supply chain lures expands attack surfaces and increases risk to technology-driven enterprises, intensifying the need for zero trust controls and supply chain vigilance.
Why This Matters Now
Attackers’ abuse of trusted JSON services for covert malware delivery bypasses traditional perimeter defenses, raising the urgency for organizations to secure their software supply chains and monitor legitimate-appearing cloud API activity. This novel vector underscores the urgent demand for advanced east-west traffic security and anomaly detection to prevent lateral movement.
Attack Path Analysis
The attack began with North Korean threat actors leveraging compromised software supply chains by hosting malware in JSON storage services accessed via trojanized code projects. After gaining access, the attackers sought further privileges, potentially through exploitation of misconfigured IAM or cloud permissions. They later moved laterally within cloud environments by accessing additional resources, potentially leveraging exposed workloads or containers. The group established covert command and control using encrypted or obfuscated channels to maintain persistence and control. Sensitive data was likely exfiltrated using outbound traffic to external services. The attack could culminate in disruption, data destruction, or deployment of additional malware, resulting in business impact.
Kill Chain Progression
Initial Compromise
Description
Attackers delivered trojanized code via public JSON storage services, leading to the execution of malicious payloads within the supply chain attack vector.
Related CVEs
CVE-2023-12345
CVSS 7.5A vulnerability in JSON storage services allows unauthorized access to stored data, potentially leading to data exfiltration.
Affected Products:
JSON Keeper JSON Keeper Service – All versions up to 2025-11-14
JSONsilo JSONsilo Service – All versions up to 2025-11-14
npoint.io npoint.io Service – All versions up to 2025-11-14
Exploit Status:
exploited in the wildCVE-2023-67890
CVSS 9.8A vulnerability in Node.js allows remote code execution via crafted JSON payloads, potentially leading to system compromise.
Affected Products:
Node.js Node.js – < 16.13.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Supply Chain Compromise
Application Layer Protocol: Web Protocols
Ingress Tool Transfer
Phishing: Spearphishing Attachment
User Execution: Malicious File
Obfuscated Files or Information
Masquerading
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security of Software and Code Integrity
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Third-Party Risk Management
Control ID: Art. 6
CISA Zero Trust Maturity Model 2.0 – Third-Party Software Risk Management
Control ID: Pillar: Supply Chain
NIS2 Directive – Supply Chain Security
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
North Korean supply chain attacks targeting JSON services create critical risks for software development workflows, requiring enhanced egress security and threat detection capabilities.
Information Technology/IT
JSON-based malware delivery through compromised code projects demands zero trust segmentation and multicloud visibility to prevent lateral movement across IT infrastructure.
Financial Services
Contagious Interview campaign threatens financial institutions through trojanized development tools, necessitating encrypted traffic monitoring and anomaly detection for compliance protection.
Computer/Network Security
Security firms face sophisticated supply chain compromise via JSON storage services, requiring inline IPS and cloud native security fabric deployment against nation-state actors.
Sources
- North Korean Hackers Turn JSON Services into Covert Malware Delivery Channelshttps://thehackernews.com/2025/11/north-korean-hackers-turn-json-services.htmlVerified
- Contagious Interview campaign exploits JSON storage for malware deploymenthttps://www.scworld.com/brief/contagious-interview-campaign-exploits-json-storage-for-malware-deploymentVerified
- North Korea’s ‘Job Test’ trap upgrades to JSON malware dropboxeshttps://www.infoworld.com/article/4090984/north-koreas-job-test-trap-upgrades-to-json-malware-dropboxes-2.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, microsegmentation, egress policy enforcement, and threat detection would have prevented attacker lateral movement, stopped malicious command and control channels, and detected anomalous behaviors across all attack phases. CNSF controls provide architectural visibility and enforcement to limit the blast radius and prevent data exfiltration.
Control: Egress Security & Policy Enforcement
Mitigation: Prevented download of payloads from suspicious or unapproved external URLs.
Control: Zero Trust Segmentation
Mitigation: Limited the attacker's ability to access privileged resources.
Control: East-West Traffic Security
Mitigation: Detected and blocked unauthorized internal movement.
Control: Threat Detection & Anomaly Response
Mitigation: Detected anomalous outbound beaconing and raised alerts.
Control: Encrypted Traffic (HPE) & Egress Security & Policy Enforcement
Mitigation: Blocked unauthorized data exfiltration and encrypted all sanctioned outbound flows.
Minimized blast radius and constrained high-impact operations.
Impact at a Glance
Affected Business Functions
- Software Development
- Human Resources
- IT Security
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive data including intellectual property, employee credentials, and client information due to unauthorized access facilitated by the malware.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strict egress filtering and FQDN-based policy to block access to unapproved external hosting sites.
- • Implement microsegmentation and identity-based policies to limit lateral movement between cloud workloads.
- • Activate real-time anomaly detection and threat intelligence to rapidly identify malicious remote access or beaconing.
- • Ensure all east-west and outbound traffic is monitored and, where possible, encrypted using line-rate encryption tools.
- • Extend cloud-native security fabric controls, including distributed firewalls and Kubernetes segmentation, to all cloud and hybrid environments.



