North Korean Hackers Hide OTTERCOOKIE Malware in SVG Images to Backdoor Developers
ID: 4857d721-836c-55dd-bb9d-a099c891b1e3
STIX ID: report--4857d721-836c-55dd-bb9d-a099c891b1e3
Feed Name: Cyber Press
Security researchers uncovered the SleeperGem supply-chain campaign where attackers published trojanized RubyGems (git_credential_manager, Dendreo, fastlane-plugin-run_tests_firebase_testlab) that deliver a native daemon and persistence on developer machines. The malicious packages avoid CI by detecting CI environment variables, download a deploy script and a native binary from an attacker-controlled Forgejo host, disable TLS verification, and attempt privilege escalation and credential theft; organizations are advised to search Gemfile.lock for affected versions, inspect user services, cron entries, and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
