OtterCookie is a JavaScript/Node.js malware family used in DPRK-linked Contagious Interview / DeceptiveDevelopment activity and associated in reporting with Lazarus-linked operations such as PurpleBravo. It is described as a separate implant from BeaverTail, though some reporting notes overlapping capabilities and delivery chains, and one source characterizes it as a BeaverTail-like evolution that appeared in late 2024. OtterCookie is commonly delivered through malicious developer lures, including trojanized GitHub repositories, fake coding tests, malicious VS Code/Cursor projects abusing .vscode/tasks.json with folder-open execution, fake .woff2 files containing JavaScript loaders, malicious npm packages, and repositories tied to fraudulent recruiting fronts. In observed chains, env-setup.js or similar bootstrap code downloads and executes OtterCookie, sometimes via Vercel-hosted staging infrastructure and blockchain dead-drop retrieval mechanisms.
Functionally, OtterCookie is characterized as an infostealer and RAT focused on active developer workstations. Reported capabilities include theft of browser credentials and browser extension data; targeting of cryptocurrency wallet artifacts and wallet browser extensions; recursive discovery and upload of sensitive files across drives; clipboard theft; keystroke logging; screenshot capture; active workspace monitoring on a 30-second interval; shell or command execution; process control; and persistent socket-based command and control. Multiple analyses describe three major script components or payload roles: a browser-data theft module, a file-upload/exfiltration module, and a socket/WebSocket or Socket.IO-based C2 module. OtterCookie has been observed stealing data from browsers including Chrome, Brave, Edge, Opera, Opera GX, Vivaldi, Kiwi, Yandex, AVG Browser, Iridium, Comodo, SRWare, and Chromium.
C2 behavior is a distinguishing feature. OtterCookie uses Socket.IO over Engine.IO v4 for command and control, maintains persistent victim sessions, and in some observed infrastructure broadcasts victim rosters at regular intervals. Reported infrastructure includes 172.86.73[.]198 with uploads to port 8086 and C2/notify traffic on port 8087; 216.126.225.243, described in the content as a known DPRK OtterCookie C2, with browser-data theft on port 8085, file upload on 8086, and /api/notify plus reverse-shell/C2 on 8087; and Hetzner host 195.201.104.53, where port 6931 was observed as a live OtterCookie Socket.IO C2 broadcasting victim state every 30 seconds and port 6101 as an apparent predecessor or reserve C2. One analyzed sample used a plaintext HMAC-SHA256 key "SuperStr0ngSecret@)@^" and Axios for HTTP POST communications.
OtterCookie is repeatedly associated with DPRK targeting of software developers, especially cryptocurrency-related victims, and with broader fake-interview and supply-chain campaigns. Reported targeted sectors include cryptocurrency, technology, education, financial services, media, telecommunications, and business services. High-confidence indicators mentioned in the content include IPs 172.86.73[.]198, 216.126.225.243, and 195.201.104.53; Vercel-hosted staging such as y-lilac-sigma.vercel[.]app and tetrismic.vercel[.]app; Socket.IO C2 ports 6931 and 6101; and one analyzed sample SHA-256 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In that woff2 file is the JavaScript loader that bootstraps the first stage of a DPRK Beavertail or Ottercookie attack chain.
This will eventually to either Ottercookie / Beavertail malware. Running the entire repository ultimately leads to an infection.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
With the unique fingerprint, we identified 77 malicious GitHub repositories... Running the entire repository ultimately leads to an infection.
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.
runOptions의 runOn 옵션이 folderOpen으로 설정되어 있어 레포지토리에 대한 폴더가 VSCode에서 열릴 경우 자동으로 삽입된 명령어가 실행되는 방식이다.
The appropriate command downloads and executes a script from the command-and-control (C&C) server.
The second-stage packages are near-identical SVG utilities that fetch a JSON object from JSONKeeper and eval the model field.
parser.js 는 obfuscator.io로 난독화가 적용된 다운로더이다... 문자열 추출 및 배열화... 실행 시 배열 셔플... 오프셋 기반 문자열 접근... 식별자 변조...
The file collector component has been found to specifically look for editor history associated with Microsoft Visual Studio Code, Windsurf, and Cursor, along with developer and AI tool configurations, such as AWS, Microsoft Azure, Google Gemini, Anthropic Claude, Foundry, SSH, and Z shell (Zsh).
These environments often have access to sensitive assets such as source code, npm tokens, Git credentials, cloud keys, SSH keys, browser data, and project secrets.
processControl 기능은 ldbScript, autoUploadScript, socketScript 를 멈추거나 다시 시작할 수 있도록 설계되어 있으나
This is a backdoor component. It first collects system information and uploads it... The collected data includes: IP-based geolocation data, ISP information, UUID, Hostname, Username, OS type, OS release, OS version.
This component performs file collection and exfiltration. It searches for and exfiltrates files matching the following patterns...
InvisibleFerret introduces additional malicious payloads into victim environments, performs information stealing and fingerprinting actions within the victim environment, and leverages legitimate protocols and software for C2 communications.
The appropriate command downloads and executes a script from the command-and-control (C&C) server... uploads the information to hxxp://66.235.175[.]117:1244/uploads.
the malware installs the necessary dependencies and reaches out to an external server ("216.126.236[.]244") to fetch an encrypted JavaScript payload.
129 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Lazarus-associated malware component in the PolinRider chain, referenced as part of the DPRK stealer toolkit delivered after the initial loader stage.
Obfuscated malware delivered via env-setup.js in the same campaign. It runs three coordinated scripts to steal browser credentials and extension data, search all drives for sensitive files and upload them, and maintain socket-based command-and-control for remote command execution and process control.
Multi-process malware that steals browser credentials and extension data, scans drives for sensitive files, uploads them to attacker infrastructure, collects host information, and maintains a socket-based command channel for remote command execution and process control.
JavaScript malware associated with Lazarus-linked npm campaigns. In this campaign, the payload behaves like a loader and backdoor with remote access capabilities, interactive terminal support, command execution, screenshot capture, process termination, Windows mouse/keyboard control, clipboard capture, and theft of browser, wallet, file, and developer-secret data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.