OtterCookie is a DPRK-linked modular JavaScript malware family associated with the Contagious Interview activity cluster targeting software developers, particularly in cryptocurrency, Web3, and related engineering roles. It is commonly delivered through fake recruiter outreach and trojanized coding challenges or repositories that appear functional while covertly executing malware. Reported delivery chains include malicious Visual Studio Code task configurations and repositories that reconstruct payloads from concealed data embedded in benign-looking assets such as SVG images, as well as npm-based supply-chain lures.
OtterCookie combines infostealing and remote-access functionality. Observed capabilities include theft of browser credentials and autofill data, collection of cryptocurrency wallet data and browser extension stores, recursive theft of sensitive files such as keys, configuration files, shell histories, cloud and SSH material, and clipboard monitoring for secrets. Multiple reports also describe a Socket.IO-based command-and-control component that provides interactive shell access and supports execution of arbitrary commands on compromised hosts. Some variants or related delivery chains also download additional payloads or Windows executables, use process masquerading, and include virtualization or sandbox checks.
The malware has been described as evolving from earlier DPRK developer-targeting tooling and is frequently discussed alongside BeaverTail and InvisibleFerret within the broader Contagious Interview ecosystem. OtterCookie infections have been observed across Windows, macOS, and Linux, reflecting the threat actor’s focus on developer workstations that often contain source code, browser sessions, cloud credentials, wallet access, and other high-value secrets. Compromise of a single developer system can create downstream supply-chain risk when stolen access or tampered repositories are later propagated into organizational environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
What lands is a four-part OtterCookie kit: a browser-and-wallet stealer, a file stealer, a Socket.IO remote-access trojan, a clipboard grabber, all delivered through fake coding-test “recruiter” lures.
Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer.
This will eventually to either Ottercookie / Beavertail malware. Running the entire repository ultimately leads to an infection.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Elastic said it discovered the campaign after the threat actors targeted members of its community Slack workspace with social engineering lures for purported job offers. | The messages, posted by a user named Maxwell on the #jobs Slack channel in late May 2026, sought an experienced developer to help with upgrading their e-commerce platform.
A helper script rebuilds the code and runs it at server start... Watch Node processes that spawn shells or PowerShell.
A JavaScript file named serverValidation.js reads the SVG files, joins the fragments, and executes the recovered code.
Attackers split the payload into Base64 chunks. Then they tucked those chunks inside SVG country-flag files.
Attackers split the payload into Base64 chunks. Then they tucked those chunks inside SVG country-flag files. A helper script rebuilds the code and runs it at server start.
developers should review server startup files and asset directories, and look closely for dynamic code execution such as eval() or code that reads image files.
The first sample copied a real Next.js store template called GoCart. That legitimate base made the trap look convincing.
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
101 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-component malware package delivered via trojanized coding-test repositories in the Contagious Interview campaign. It steals browser credentials, crypto wallet data, developer files such as keys/configs/source code, includes a Socket.IO backdoor for live shell access, and monitors the clipboard for copied secrets across Windows, macOS, and Linux.
Malware hidden in SVG image assets within a fake coding-test project. When the server starts, a JavaScript loader reconstructs and executes the payload. The toolkit includes a browser credential and cryptocurrency-wallet stealer, a file stealer, a clipboard collector, and a Socket.IO-based remote access component for command execution.
A malware payload delivered in a four-stage Contagious Interview infection chain used against software developers via fake job postings and malicious coding challenges.
A modular malware kit used in North Korea-linked Contagious Interview activity, delivering browser and cryptocurrency wallet theft, file theft, remote access via Socket.IO, and clipboard theft through fake recruiter/coding-test lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.