ATT&CKSoftwareHexEval Loader

HexEval Loader

S1249

Malware.View on attack.mitre.org

About this malware

HexEval Loader is a hex-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail malware. HexEval Loader was first reported in April 2025. HexEval Loader has previously been leveraged by North Korea-affiliated threat actors identified as Contagious Interview. HexEval Loader has been delivered to victims through code repository sites utilizing typosquatting naming conventions of various npm packages.

Techniques used12

Procedure examples12

TechniqueProcedure example
T1016
System Network Configuration Discovery

HexEval Loader has leveraged server-side client configurations to identify the public IP of the victim host.

T1027.013
Encrypted/Encoded File

HexEval Loader has encoded module names and C2 URLs as hexadecimal strings in attempts to evade analysis.

T1033
System Owner/User Discovery

HexEval Loader has collected the username from the victim host.

T1036.005
Match Legitimate Resource Name or Location

HexEval Loader has masqueraded and typosquatted as legitimate code repository packages and projects.

T1041
Exfiltration Over C2 Channel

HexEval Loader has exfiltrated victim data using HTTPS POST requests to its C2 servers.

T1056.001
Keylogging

HexEval Loader has utilized a cross-platform keylogger that has the capability to capture keystrokes on Windows, macOS and Linux systems.

T1059.007
JavaScript

HexEval Loader has executed malicious JavaScript code.

T1071.001
Web Protocols

HexEval Loader has used HTTP and HTTPS POST requests to communicate with C2.

T1082
System Information Discovery

HexEval Loader has identified the OS and MAC address of victim device through host fingerprinting scripting.

T1105
Ingress Tool Transfer

HexEval Loader has been used to download a malicious payload to include BeaverTail.

T1140
Deobfuscate/Decode Files or Information

HexEval Loader has decoded its payload prior to execution.

T1614
System Location Discovery

HexEval Loader has a function where the C2 endpoint can identify the geographical location of a victim host based on request headers, execution environment and runtime conditions.

Groups that use it1

Campaigns0

None recorded.

References3

  1. Socket BeaverTail XORIndex HexEval Contagious Interview July 2025 Open source
    Kirill Boychenko. (2025, July 14). Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader. Retrieved October 19, 2025.
  2. Socket Contagious Interview NPM April 2025 Open source
    Kirill Boychenko. (2025, April 4). Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads. Retrieved October 20, 2025.
  3. Socket HexEval BeaverTail Contagious Interview June 2025 Open source
    Kirill Boychenko. (2025, June 25). Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages. Retrieved October 19, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.