BeaverTail is a JavaScript-based malware family associated with North Korea-linked Contagious Interview activity and publicly linked to Lazarus-aligned operations including DEV#POPPER and related supply-chain clusters such as PolinRider. It is primarily used against software developers, especially individuals working in cryptocurrency, Web3, DeFi, and adjacent technology sectors, where access to source code, credentials, browser data, and wallet material is especially valuable.
BeaverTail functions chiefly as an infostealer and downloader. Observed variants collect host information, steal browser-stored credentials, harvest browser extension data with a strong emphasis on cryptocurrency wallet extensions, and search for sensitive developer and wallet-related files such as environment files, configuration files, key material, password stores, and project secrets. Some variants also include backdoor-style components that transmit system metadata, maintain socket-based command channels, execute remote shell commands, terminate processes, upload files, and fetch or run additional JavaScript payloads. BeaverTail commonly downloads and launches the Python-based InvisibleFerret malware as a follow-on stage, extending the intrusion into broader post-compromise access, surveillance, and theft.
Delivery has been observed through multiple social-engineering and software supply-chain mechanisms. In recruiter-themed campaigns, operators pose as employers or collaborators and trick victims into opening malicious repositories, coding tests, interview projects, or fake conferencing and development applications. In developer-tooling abuse, BeaverTail has been triggered through malicious Visual Studio Code task configurations that execute automatically when a repository is opened. In supply-chain operations, it has been embedded in malicious npm packages, hidden in obfuscated JavaScript appended to legitimate project configuration files, concealed in fake font files, and propagated through compromised GitHub repositories and package ecosystems including npm, Go modules, and Composer/Packagist. Recent campaigns also used blockchain-based dead-drop or EtherHiding-style retrieval to obtain encrypted second-stage content, complicating static detection and infrastructure takedown.
The malware is cross-platform, with confirmed execution paths for Windows, macOS, and Linux. On Windows, some chains additionally fetch a Python runtime to ensure execution of later Python payloads. Operational reporting consistently ties BeaverTail to financially motivated theft and espionage, with particular focus on cryptocurrency assets, developer secrets, and long-term access to targeted environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In that woff2 file is the JavaScript loader that bootstraps the first stage of a DPRK Beavertail or Ottercookie attack chain.
The PolinRider threat group was first detected this year when cybersecurity analysts identified hundreds of GitHub repositories with hidden JavaScript code that downloads an updated version of the BeaverTail malware.
This will eventually to either Ottercookie / Beavertail malware. Running the entire repository ultimately leads to an infection.
Instructional videos have also been found with what it looks like non-native English text, detailing how to set up a Beavertail malware command-and-control server and how to crack cryptocurrency wallet passwords.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
PolinRider is a DPRK-linked supply-chain campaign... takes over legitimate GitHub accounts and quietly injects an obfuscated JavaScript loader into repositories the maintainer already owns.
runOptions의 runOn 옵션이 folderOpen으로 설정되어 있어 레포지토리에 대한 폴더가 VSCode에서 열릴 경우 자동으로 삽입된 명령어가 실행되는 방식이다.
Malicious npm package posing as a Tailwind utility; functional decoy in index.ts
Posing as recruiters or colleagues... Lazarus initiates conversations... moving communications to private messaging platforms like WhatsApp to build trust.
Most of the time, the payload will be in the tasks.json file... a command that runs uses node to run one of the files pretending to be font files.
The appropriate command downloads and executes a script from the command-and-control (C&C) server.
The same four infection methods and the same loader we documented on GitHub carried over into Go and Packagist: Obfuscated JavaScript appended to config files... | If you look at line 16 of the tasks.json file, you’ll see a command that runs uses node to run one of the files pretending to be font files: fa-solid-400.woff2.
Most of the time, the payload will be in the tasks.json file... a command that runs uses node to run one of the files pretending to be font files.
After the initial compromise, the attackers’ BeaverTail malware searches the project directory for the most common JavaScript configuration files and other relevant files such as Tailwind CSS, Next.js, Babel, and ESLint files. It then stealthily inserts malicious code into the files.
takes over legitimate GitHub accounts and quietly injects an obfuscated JavaScript loader into repositories...
The payload hides in config files, fake .woff2 font files, and .vscode/tasks.json triggers... one or more of those fonts is actually malicious JavaScript.
Additionally, the malware tampers with the Git commit history to hide its tracks by overwriting commit messages and timestamps.
The loader still resolves its second stage from blockchain dead-drops across TRON, Aptos, and BNB Smart Chain, decrypts it with embedded XOR keys...
The appropriate command downloads and executes a script from the command-and-control (C&C) server... uploads the information to hxxp://66.235.175[.]117:1244/uploads.
For FTP uploads, the C&C server provides the domain, username, and password.
The payload hides in config files... then uses blockchain dead-drops to download the Lazarus stealer toolkit.
The loader still resolves its second stage from blockchain dead-drops across TRON, Aptos, and BNB Smart Chain, decrypts it with embedded XOR keys, and runs it through eval().
332 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
168 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BeaverTail3
A Lazarus-associated loader used as part of the PolinRider infection chain to fingerprint the host OS and bootstrap follow-on implants.
BeaverTail3
JavaScript-based malware delivered in the Contagious Interview campaign. It uses staged components (test.js, n.js, p.js) to collect browser credentials and extension data, download and launch InvisibleFerret, establish backdoor access, execute commands, and search for and exfiltrate sensitive files including wallet- and credential-related material.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.