logo

Fake Gemini npm Package Steals AI Tool Tokens

ID: 5187d286-c626-5ee3-ac60-395645636d77

STIX ID: report--5187d286-c626-5ee3-ac60-395645636d77

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A malicious npm package 'gemini-ai-checker' posing as a Gemini-themed utility delivered an in-memory, obfuscated JavaScript backdoor (likely an OtterCookie variant) via a Vercel-hosted endpoint; the payload spawns multiple Node.js processes implementing Socket.IO RAT/C2, credential theft (including browser wallets and AI-tool API keys), file exfiltration, and clipboard stealing. The campaign targeted directories used by AI coding tools (Cursor, Claude, Gemini CLI, Windsurf, PearAI, EigenT), included hardcoded C2 infrastructure and tokens, received hundreds of downloads across related packages, and is tied with moderate-to-high confidence to a DPRK-linked 'Contagious Interview' activity; the report provides IOCs and recommends monitoring/takedown, restricting outbound Vercel connections, and inspecting packages for mismatched README or post-install network behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.