logo

Hackers Use Fake Gemini npm Package to Steal Tokens From Claude, Cursor, and Other AI Tools

ID: 6f98a5d0-8004-510f-9ac5-4891f784ec97

STIX ID: report--6f98a5d0-8004-510f-9ac5-4891f784ec97

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-07

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious npm package 'gemini-ai-checker' was published to target AI software developers by fetching and executing an in-memory JavaScript payload (OtterCookie) from a Vercel staging endpoint; the backdoor, attributed to a DPRK-linked campaign, exfiltrates browser credentials, over 25 cryptocurrency wallets, AI tool directories (Cursor, Claude, Windsurf, PearAI, Gemini CLI, Eigent AI), and source files, communicates with C2 at 216.126.237.71, and seeks to evade detection via fragmented C2 strings and in-memory execution; defenders are advised to monitor/block Vercel outbound traffic, verify npm package contents, and use KQL/Node.js process detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.