logo

North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens

ID: 31d6a759-3c64-5468-8b18-35133b9945fc

STIX ID: report--31d6a759-3c64-5468-8b18-35133b9945fc

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-10

Date Updated: 2026-04-23

Author: Ddos

...
...

North Korean-linked threat actors deployed malicious npm packages (notably gemini-ai-checker) that contain a fileless OtterCookie backdoor designed to steal AI tool tokens (Cursor, Claude, Gemini, Windsurf), browser credentials, crypto wallets and sensitive files. The malware uses a four-module architecture (RAT, credential stealer, file exfiltration, clipboard stealer), runs entirely in memory to evade detection, and the campaign remains active with multiple malicious packages observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.