logo

North Korean Hackers Exploiting npm, GitHub, and Vercel to Deliver OtterCookie Malware

ID: bd486ea9-bf6d-5183-8ee3-0462f19a7ce8

STIX ID: report--bd486ea9-bf6d-5183-8ee3-0462f19a7ce8

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-11-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

North Korean state-sponsored actors operating the "Contagious Interview" campaign are distributing the OtterCookie infostealer/RAT via typosquatted npm packages and GitHub/Vercel staging that execute postinstall scripts to fetch and eval payloads; researchers identified ~197 malicious packages and ~31,000 downloads, with active C2 at 144.172.104.117. The malware targets developer workflows and Web3 assets across Windows, macOS, and Linux, implements persistence, sandbox-evasion checks, keylogging, screenshot capture, and exfiltration of browser credentials and cryptocurrency wallet data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.