North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware
These articles are AI-generated summaries. Please check the original sources for full details.
North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware
North Korean threat actors expanded the Contagious Interview campaign by deploying 197 new npm packages, which have been downloaded over 31,000 times. These packages deliver a hybrid OtterCookie malware variant combining features of BeaverTail and prior iterations.
Why This Matters
The attack underscores the vulnerability of JavaScript ecosystems to supply-chain compromises. While npm packages are typically trusted, this campaign exploits developer reliance on third-party libraries. The malware evades sandboxing, establishes persistent C2 channels, and exfiltrates sensitive data, including cryptocurrency credentials. The scale of downloads highlights the risk of weaponized open-source dependencies, with potential for widespread compromise across development environments.
Key Insights
- “197 npm packages, 31,000+ downloads, 2025”: Socket analysis reveals the scope of the Contagious Interview campaign.
- “Sandbox evasion + C2 persistence”: OtterCookie combines evasion techniques with long-term access via hard-coded Vercel URLs and GitHub repos.
- “Fake interview schemes”: Attackers use job interview simulations to trick users into executing malicious Node.js apps.
Practical Applications
- Use Case: Fake assessment sites mimic Chrome prompts to steal credentials under the guise of camera/microphone fixes.
- Pitfall: Trusting unverified npm packages without code review or dependency checks can introduce persistent backdoors.
References:
Continue reading
Next article
Data Contracts: Bridging the Gap Between Data Producers and Consumers
Related Content
North Korea-Linked Hackers Target Developers via Malicious VS Code Projects
North Korean hackers are exploiting Visual Studio Code task files in fake job projects to deploy backdoors and crypto miners, demonstrating a sophisticated evolution in attack tactics.
North Korean PurpleBravo Campaign Targeted 3,136 IPs via Fake Job Interviews
North Korean PurpleBravo hackers targeted 3,136 IP addresses and 20 companies with malicious VS Code projects and BeaverTail malware.
China-Linked Hackers Utilize PeckBirdy JavaScript C2 Framework
Experts reveal PeckBirdy, a JavaScript C2 framework used by China-aligned attackers to spread malware via fake updates and web injections since 2023.