SYMBOLCOMMON_NAMEaka. SYNONYMS
js.jadesnow (Back to overview)

JADESNOW

aka: ChainedDown

Actor(s): WageMole


JADESNOW is a JavaScript-based downloader malware family associated with the threat cluster UNC5342. JADESNOW utilizes EtherHiding to fetch, decrypt, and execute malicious payloads from smart contracts on the BNB Smart Chain and Ethereum. The input data stored in the smart contract may be Base64-encoded and XOR-encrypted. The final payload in the JADESNOW infection chain is usually a more persistent backdoor like INVISIBLEFERRET.JAVASCRIPT.

References
2026-08-10 ⋅ sonatype ⋅ Sonatype Research Team
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
JADESNOW
2026-07-29 ⋅ SafeDep ⋅ SafeDep Team
Joyfill npm Packages Compromised with Blockchain C2 Loader
JADESNOW
2026-07-28 ⋅ StepSecurity ⋅ Varun Sharma
Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan
JADESNOW
2026-07-28 ⋅ Socket ⋅ Socket Research Team
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
JADESNOW
2026-07-17 ⋅ OpenSourceMalware ⋅ Jenn Gile
ChainVeil and ViteVenom are DPRK’s PolinRider Campaign
JADESNOW
2026-07-15 ⋅ OpenSourceMalware ⋅ Paul McCarty
PolinRider Confirmed Footprint Grows 6.5x Since March
JADESNOW
2026-07-14 ⋅ Checkmarx ⋅ Pavan Gudimalla
Sequel to ChainVeil npm Malware Targets Vite Ecosystem
JADESNOW
2026-07-01 ⋅ Socket ⋅ Karlo Zanki
PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems
JADESNOW
2026-06-24 ⋅ JFrog Security ⋅ Guy Korolevski, Yair Benamou
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
JADESNOW
2026-06-22 ⋅ Melted in Hex ⋅ Melted in Hex
Dead Drops on the Blockchain: Reversing a DPRK npm Loader (PolinRider / A6-Shadow-15)
JADESNOW
2026-06-16 ⋅ Checkmarx ⋅ Pavan Gudimalla
ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey
JADESNOW
2026-06-12 ⋅ SafeDep ⋅ SafeDep
astro.config.mjs Supply Chain Attack via Blockchain C2
JADESNOW
2026-05-31 ⋅ Socket ⋅ Kirill Boychenko
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
JADESNOW
2026-04-21 ⋅ Trend Micro ⋅ Lucas Silva
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
BeaverTail JADESNOW OtterCookie InvisibleFerret
2026-04-03 ⋅ Casco ⋅ Rene Brandel
The Blueprint of a North Korean Attack on Open-Source
JADESNOW
2026-03-07 ⋅ OpenSourceMalware ⋅ OpenSourceMalware
PolinRider: DPRK Threat Actor Implants Malware in Hundreds of GitHub Repos
JADESNOW
2026-03-05 ⋅ eSentire ⋅ eSentire Threat Response Unit (TRU)
North Korean APT Malware Analysis: DEV#POPPER RAT and OmniStealer (Everyday I'm Shufflin')
JADESNOW
2026-01-13 ⋅ Medium @0xOZ ⋅ OZ
How to Get Scammed (by DPRK Hackers)
JADESNOW
2025-12-17 ⋅ Crystal Intelligence ⋅ Crystal Intelligence
How we proved North Korea’s blockchain malware campaign
JADESNOW
2025-12-08 ⋅ Ransom-ISAC ⋅ Andrii Sovershennyi, Nick Smart
Cross-Chain TxDataHiding Crypto Heist: A Very (Very) Chainful Process (Part 4)
JADESNOW
2025-11-13 ⋅ Ransom-ISAC ⋅ Yashraj Solanki
Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 3)
JADESNOW
2025-10-27 ⋅ Ransom-ISAC ⋅ Ellis Stannard
Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 2)
JADESNOW
2025-10-20 ⋅ Ransom-ISAC ⋅ Ellis Stannard
Cross-Chain TxDataHiding Crypto Heist: A Very Chainful Process (Part 1)
JADESNOW
2025-10-16 ⋅ Mandiant ⋅ Blas Kojusner, Joseph Dobson, Robert Wallace
DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains
JADESNOW UNC5342
2025-09-30 ⋅ kuxhagra ⋅ Kushagra Sarathe
that one time i got hacked: a security incident breakdown
JADESNOW
2025-06-12 ⋅ Aikido ⋅ Charlie Eriksen
A deeper look into the threat actor behind the react-native-aria attack
JADESNOW
2025-06-06 ⋅ Aikido ⋅ Charlie Eriksen
RATatouille: A Malicious Recipe Hidden in rand-user-agent (Supply Chain Compromise)
JADESNOW

There is no Yara-Signature yet.