Malware
OtterCookie
Indicators of Compromise 43
Domain bitbucket[.]org Domain jsonkeeper[.]com Filename raw.js Filename serverValidation.js Filename test.list GitHub Repo Maxwell GitHub Repo marketfront SHA-256 0904eff1edeff4b6eb27f03e0ccc759d6aa8d4e1317a1e6f6586cdb84db4a731 SHA-256 51ddd8f6ff30d76de45e06902c45c55163ddbec7d114ad89b21811ffedb71974 SHA-256 6a9b4e8537bb97e337627b4dd1390bdb03dc66646704bd4b68739d499bd53063 SHA-256 72ebfe69c69d2dd173bb92013ab44d895a3367f91f09e3f8d18acab44e37b26d SHA-256 77aec48003beeceb88e70bed138f535e1536f4bbbdff580528068ad6d184f379 SHA-256 83c145aedfdf61feb02292a6eb5091ea78d8d0ffaebf41585c614723f36641d8 SHA-256 8efa928aa896a5bb3715b8b0ed20881029b0a165a296334f6533fa9169b4463b SHA-256 9e65de386b40f185bf7c1d9b1380395e5ff606c2f8373c63204a52f8ddc01982 SHA-256 a6914ded72bdd21e2f76acde46bf92b385f9ec6f7e6b7fdb873f21438dfbff1d SHA-256 caad2f3d85e467629aa535e0081865d329c4cd7e6ff20a000ea07e62bf2e4394 SHA-256 d27c9f75c3f1665ee19642381a4dd6f2e4038540442cf50948b43f418730fd0a SHA-256 d89c45d65a825971d250d12bc7a449321e1977f194e52e4ca541e8a908712e47 SHA-256 dff2a0fb344a0ad4b2c129712b2273fda46b5ea75713d23d65d5b03d0057f6dd SHA-256 f08e3ee84714cc5faefb7ac300485c879356922003d667587c58d594d875294e IP 135[.]181[.]123[.]177 IP 138[.]201[.]50[.]5 IP 142[.]93[.]211[.]30 IP 144[.]172[.]112[.]50 IP 144[.]172[.]96[.]35 IP 172[.]86[.]113[.]12 IP 172[.]86[.]73[.]46 IP 172[.]86[.]88[.]188 IP 216[.]126[.]236[.]244 IP 23[.]227[.]202[.]244 Package events-runtime Package express-session-js Package node-nvm-ssh Package o3forms Package quirky-token Package react-icon-svgs Package rollup-packages-polyfill-core Package rollup-plugin-polyfill-connect Package rollup-runtime-polyfill-core Package security-alerts-sdk Package swift-parse-stream Registry User marketfront
MITRE ATT&CK TTPs 19
T1003 T1005 T1027 T1056.001 T1056.002 T1059.001 T1059.007 T1071 T1071.001 T1071.003 T1082 T1083 T1110 T1113 T1114 T1123 T1195.002 T1555 T1566
OS Credential Dumping
Credential Access
Data from Local System
Collection
Obfuscated Files or Information
Defense Evasion
Keylogging
Collection
GUI Input Capture
Collection
PowerShell
Execution
JavaScript
Execution
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Mail Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Brute Force
Credential Access
Screen Capture
Collection
Email Collection
Collection
Audio Capture
Collection
Compromise Software Supply Chain
Initial Access
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Source Articles
BeaverTail and OtterCookie evolve with a new Javascript module
Cisco Talos identified a new attack campaign linked to the DPRK-aligned threat group Famous Chollima, which uses social engineering through fake job offers to distribute trojanized Node.js applications. The campaign leverages malicious npm packages like 'node-nvm-ssh' and combines the BeaverTail and OtterCookie malware tools to steal credentials, cryptocurrency wallets, and system information. Recent evolution includes merged functionality between BeaverTail and OtterCookie, with new capabilities such as keylogging, screenshot capture, and clipboard monitoring delivered via a modular JavaScript-based framework.
talos
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors linked to the Contagious Interview campaign are targeting software developers through fake job postings and coding challenges. They distribute malicious repositories that include SVG images with steganographically hidden payloads, which deploy the OtterCookie malware. This multi-stage malware steals browser credentials, cryptocurrency wallets, files, and clipboard data, while also enabling remote access via a Socket.IO-based backdoor.
hacker-news ·1mo ago
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
North Korean threat actors have been linked to a software supply chain attack involving malicious npm packages that impersonate legitimate Rollup polyfill tools. The packages, such as 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core', install secondary-stage malicious dependencies to steal developer secrets and enable remote access. The malware evades analysis environments, exfiltrates credentials, and supports interactive command execution, targeting developer workstations and CI/CD systems. This activity mirrors previous Lazarus-linked campaigns exploiting npm for credential theft.
hacker-news ·2mo ago