HexEval Loader
S1249 · Linux, macOS, Windows
HexEval Loader is a hex-encoded loader that collects host data, decodes follow-on scripts and acts as a downloader for the BeaverTail malware. HexEval Loader was first reported in April 2025. HexEval Loader has previously been leveraged by North Korea-affiliated threat actors identified as Contagious Interview.
HexEval Loader has been delivered to victims through code repository sites utilizing typosquatting naming conventions of various npm packages.
ATT&CK S1249
Sigma rules0
YARA rules0
Live IOCs0