logo

North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets

ID: 9d20c567-e667-50f5-a073-3d76aa2c3125

STIX ID: report--9d20c567-e667-50f5-a073-3d76aa2c3125

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-11

Date Updated: 2026-04-23

Author: Ddos

...
...

eSentire’s TRU uncovered DEV#POPPER, a sophisticated North Korean APT-linked campaign that lures developers to a malicious GitHub repo ("ShoeVista") whose hidden script retrieves obfuscated payloads from blockchain transactions to deploy a cross-platform RAT and OmniStealer targeting crypto wallets, developer credentials, and cloud tokens; the malware uses anti-analysis and environment checks, persists by injecting into Node.js applications (e.g., VS Code, Discord), exfiltrates data to C2 or Telegram, and eSentire published DEV#STOPPER.js to assist deobfuscation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.