The Containment Era is here. →Explore

Executive Summary

In late 2025, security researchers from NVISO identified a new supply chain attack campaign attributed to North Korean threat actors, leveraging popular JSON storage services—such as JSON Keeper, JSONsilo, and npoint.io—to covertly distribute trojanized malware payloads. The attackers embedded malicious code in legitimate-looking coding projects and lured developers, weaponizing widely used file formats and cloud APIs as their delivery mechanism. Consequently, targeted organizations experienced risks of credential theft, data exfiltration, and potential network breaches, with increased threat visibility due to attackers’ creative use of benign infrastructure as covert command and control channels.

This incident highlights a broader trend: state-sponsored actors are rapidly innovating malware delivery by abusing cloud-based, trusted SaaS platforms. The use of developer-centric resources and supply chain lures expands attack surfaces and increases risk to technology-driven enterprises, intensifying the need for zero trust controls and supply chain vigilance.

Why This Matters Now

Attackers’ abuse of trusted JSON services for covert malware delivery bypasses traditional perimeter defenses, raising the urgency for organizations to secure their software supply chains and monitor legitimate-appearing cloud API activity. This novel vector underscores the urgent demand for advanced east-west traffic security and anomaly detection to prevent lateral movement.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The attackers leveraged legitimate JSON storage services and disguised malicious payloads as part of authentic development tools, effectively blending into normal network activity.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying Zero Trust segmentation, microsegmentation, egress policy enforcement, and threat detection would have prevented attacker lateral movement, stopped malicious command and control channels, and detected anomalous behaviors across all attack phases. CNSF controls provide architectural visibility and enforcement to limit the blast radius and prevent data exfiltration.

Initial Compromise

Control: Egress Security & Policy Enforcement

Mitigation: Prevented download of payloads from suspicious or unapproved external URLs.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limited the attacker's ability to access privileged resources.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Detected and blocked unauthorized internal movement.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: Detected anomalous outbound beaconing and raised alerts.

Exfiltration

Control: Encrypted Traffic (HPE) & Egress Security & Policy Enforcement

Mitigation: Blocked unauthorized data exfiltration and encrypted all sanctioned outbound flows.

Impact (Mitigations)

Minimized blast radius and constrained high-impact operations.

Impact at a Glance

Affected Business Functions

  • Software Development
  • Human Resources
  • IT Security
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive data including intellectual property, employee credentials, and client information due to unauthorized access facilitated by the malware.

Recommended Actions

  • Enforce strict egress filtering and FQDN-based policy to block access to unapproved external hosting sites.
  • Implement microsegmentation and identity-based policies to limit lateral movement between cloud workloads.
  • Activate real-time anomaly detection and threat intelligence to rapidly identify malicious remote access or beaconing.
  • Ensure all east-west and outbound traffic is monitored and, where possible, encrypted using line-rate encryption tools.
  • Extend cloud-native security fabric controls, including distributed firewalls and Kubernetes segmentation, to all cloud and hybrid environments.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image