logo

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

ID: 4df67672-5826-5f9c-ad48-1b958195a2b8

STIX ID: report--4df67672-5826-5f9c-ad48-1b958195a2b8

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: [email protected] (The Hacker News)

...
...

North Korean-linked threat actors (REF9403/Contagious Interview) targeted software developers via fake job postings and trojanized coding assessments that hide Base64-encoded payload fragments inside SVG image comments. A JavaScript loader reassembles the fragments into a four-stage OtterCookie-derived malware (browser and crypto wallet stealer, file stealer, Socket.IO-based RAT, clipboard stealer), enabling data exfiltration, persistent remote access, and supply-chain risk to downstream organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.