logo

North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers

ID: 4857d721-836c-55dd-bb9d-a099c891b1e3

STIX ID: report--4857d721-836c-55dd-bb9d-a099c891b1e3

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Varshini

...
...

Security researchers uncovered the SleeperGem supply-chain campaign where attackers published trojanized RubyGems (git_credential_manager, Dendreo, fastlane-plugin-run_tests_firebase_testlab) that deliver a native daemon and persistence on developer machines. The malicious packages avoid CI by detecting CI environment variables, download a deploy script and a native binary from an attacker-controlled Forgejo host, disable TLS verification, and attempt privilege escalation and credential theft; organizations are advised to search Gemfile.lock for affected versions, inspect user services, cron entries, and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.