BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Hunting the Contagious Trader Delivery Network\n   T
 ags: Recon Village | Creator Workshop\n   When: Saturday\, Aug 8\, 10:00 -
  12:30 PDT\n   Where: LVCCW Level 1 Hall 2 501 (Recon Village) - [1]Map\n\
 n   Description:\n\n   North Korean threat actors are running one of the l
 argest software\n   supply chain campaigns ever observed in the npm ecosys
 tem\, and the\n   infrastructure hiding it in plain sight is discoverable 
 through\n   open-source reconnaissance alone.\n\n   This workshop walks pa
 rticipants through how we mapped a live DPRK\n   delivery network targetin
 g cryptocurrency developers\, starting from a\n   single malicious npm pac
 kage and expanding outward to uncover 50+\n   malicious packages\, 100+ Gi
 tHub repositories\, 30+ throwaway npm\n   personas\, 20+ rotating C2 domai
 ns\, and a social media promotion layer\n   spanning X and Reddit.\n\n   T
 he investigation surfaces three malware families: PromptMink\,\n   ClipVip
 er\, and OtterCookie\, which operate through what initially\n   appeared t
 o be separate campaigns but share overlapping\n   infrastructure\, actors\
 , and delivery techniques.\n\n   The workshop focuses on the recon methodo
 logy behind the mapping\n   through six hands-on modules:\n\n     * \n\n  
      Dependency chain tracing: How malicious payloads hide one to three\n 
       hops deep in transitive npm dependencies\, evading surface-level\n  
      code review and automated scanners\n\n     * \n\n       Actor network
  pivoting: Using email patterns\, SSH key reuse\,\n       shared C2 infras
 tructure\, and build artifact fingerprints to link\n       30+ throwaway n
 pm accounts into operational clusters\n\n     * \n\n       Identity spoofi
 ng detection: How to catch developer identity theft\n       through timezo
 ne offset analysis\n\n     * \n\n       GitHub delivery front reconnaissan
 ce: Tracing 40+ fork chains\n       across front organizations all serving
  identical malicious\n       payloads behind bot-inflated star counts and 
 SEO-stuffed\n       descriptions\n\n     * \n\n       Social media promoti
 on mapping: Connecting verified X accounts and\n       Reddit personas to 
 the distribution layer\, and observing how the\n       social infrastructu
 re persists even after GitHub takedowns\n\n     * \n\n       Evasion track
 ing in real time: Documenting the operators' shift\n       from obfuscated
  JavaScript to on-chain payload storage via Solana\,\n       where the npm
  package contains zero malicious code and the payload\n       lives in a b
 lockchain account beyond the reach of static analysis\n\n   Participants w
 ork directly with actionable IoCs (packages\, C2 domains\,\n   SSH keys\, 
 YARA rules\, detection queries) and leave with a breakdown of\n   how curr
 ent Contagious Interview and Contagious Trader toolsets are\n   converging
  into a unified threat.\n\n   Attendees will leave with a repeatable frame
 work for mapping supply\n   chain malware delivery networks using open-sou
 rce data: package\n   registries\, Git metadata\, DNS records\, social med
 ia artifacts\, and\n   cross-referencing with community threat feeds.\n\n 
   Speakers:Alessandra Rizzo\,Ariel Ropek\n\n   SpeakerBio:  Alessandra Riz
 zo\n   No BIO available\n   SpeakerBio:  Ariel Ropek\n   No BIO available\
 n   '\n\n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20260808T193000Z
DTSTART:20260808T170000Z
LOCATION:Recon Village - LVCCW Level 1 Hall 2 501 (Recon Village)
SUMMARY:Hunting the Contagious Trader Delivery Network
END:VEVENT
END:VCALENDAR
