JADESNOW is a JavaScript-based downloader/loader malware family associated with the DPRK-linked threat cluster UNC5342 and used in the Contagious Interview social-engineering campaign. It is delivered to targets—primarily software, web, and cryptocurrency developers—through fake recruiter and job interview lures, including technical assessments, malicious GitHub repositories, and npm-hosted components. Public reporting also ties infections to compromised websites and fake interview workflows.
Its core function is to fetch, decrypt, and execute additional payloads using the EtherHiding technique. JADESNOW retrieves malicious code from smart contracts and related blockchain data on Ethereum and BNB Smart Chain, typically via read-only blockchain/API queries, with reported payload data being Base64-encoded and XOR-encrypted in some cases. This blockchain-backed delivery makes the infrastructure more resilient to domain/IP blocking and takedown.
JADESNOW is used as an early-stage component in multi-stage infections and has been observed alongside BeaverTail and InvisibleFerret. Its primary downstream payload is INVISIBLEFERRET, including a JavaScript variant, which provides persistent remote access and supports long-term espionage, credential theft, cryptocurrency theft, and data exfiltration. Reporting states the broader infection chain targets browser credentials, browser extension data, credit card data, and cryptocurrency wallet data including MetaMask and Phantom. The malware has been described as querying blockchain contracts or transaction-linked data to obtain encrypted JavaScript payloads that are then executed locally or in memory. High-confidence associations in the content link JADESNOW to North Korean operations focused on both financial theft and espionage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
It targets developers with fake job offers to deliver the JADESNOW loader and INVISIBLEFERRET backdoor.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
...attacker first gains access to a legitimate website... injects... JavaScript... When a user visits the compromised website, the loader script executes in their browser...
JADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342. JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum.
JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted.
Traditionally, defenders could disrupt attacks by seizing domains or sinkholing IP addresses; however, the integration of blockchain technology renders these methods largely obsolete. By leveraging public ledgers, threat actors have created a resilient C2 layer...
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader used in the Contagious Interview campaign to deliver follow-on malware to targeted developers.
A named malware/tool associated with DPRK-linked GitHub repository compromise and blockchain-focused theft campaigns.
JADESNOW is referenced as a malware downloader and dropper, likely used in campaigns leveraging EtherHiding techniques for payload delivery and initial infection vectors.
JavaScript-based downloader/loader that retrieves a JavaScript payload from data embedded in BNB Smart Chain/Ethereum smart contracts (via read-only calls) and executes it locally to launch the next-stage backdoor (INVISIBLEFERRET).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.