BeaverTail is a JavaScript malware family associated with DPRK-linked Contagious Interview activity and related developer-focused supply-chain operations, including DEV#POPPER and PolinRider. It is commonly used as an early-stage payload that targets software developers through fake job interviews, coding challenges, trojanized repositories, malicious npm packages, and tampered developer tooling. Across campaigns, BeaverTail has been delivered through recruiter lures, malicious dependencies, VS Code task execution, and trojanized JavaScript or Electron projects, and has also been observed in developer-oriented repositories that execute when victims install dependencies or start local development servers.
BeaverTail primarily functions as a loader and stealer. It fingerprints the host, collects system information, steals browser-stored credentials and cryptocurrency wallet extension data, and searches for sensitive files such as cloud credentials, SSH material, environment files, source code, and wallet-related artifacts. Variants have targeted Chromium-based browsers across Windows, macOS, and Linux, and some samples also accessed macOS keychain data. Several campaigns show BeaverTail downloading and launching follow-on malware, most notably InvisibleFerret, while other reporting places it in chains alongside OTTERCOOKIE or additional remote-access components.
Operationally, BeaverTail has been used to establish follow-on access by retrieving later-stage implants, opening socket-based command channels, executing shell commands, uploading files, and in some cases downloading platform-specific secondary payloads. In supply-chain intrusions, BeaverTail-related loaders have been hidden in configuration files, fake font assets, SVG steganography, and malicious package code, with obfuscation and anti-tamper logic used to hinder analysis. Some campaigns also modified project files and concealed changes through Git history tampering after compromising maintainer accounts or repositories.
Targeting has consistently centered on developers, especially those in cryptocurrency, Web3, DeFi, cybersecurity, and technology sectors, because infected workstations often contain source code, tokens, cloud credentials, browser sessions, and wallet data. BeaverTail is notable for enabling both espionage and financially motivated theft, particularly cryptocurrency theft, while also serving as a staging mechanism for more persistent backdoor or RAT functionality delivered in later phases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Malware / Outils # OTTERCOOKIE (stealer) BEAVERTAIL (loader) Socket.IO RAT (rat)
The PolinRider threat group was first detected this year when cybersecurity analysts identified hundreds of GitHub repositories with hidden JavaScript code that downloads an updated version of the BeaverTail malware.
This will eventually to either Ottercookie / Beavertail malware. Running the entire repository ultimately leads to an infection.
Instructional videos have also been found with what it looks like non-native English text, detailing how to set up a Beavertail malware command-and-control server and how to crack cryptocurrency wallet passwords.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
PolinRider is a DPRK-linked supply-chain campaign... takes over legitimate GitHub accounts and quietly injects an obfuscated JavaScript loader into repositories the maintainer already owns.
runOptions의 runOn 옵션이 folderOpen으로 설정되어 있어 레포지토리에 대한 폴더가 VSCode에서 열릴 경우 자동으로 삽입된 명령어가 실행되는 방식이다.
Malicious npm package posing as a Tailwind utility; functional decoy in index.ts
Most of the time, the payload will be in the tasks.json file... a command that runs uses node to run one of the files pretending to be font files.
The appropriate command downloads and executes a script from the command-and-control (C&C) server.
takes over legitimate GitHub accounts and quietly injects an obfuscated JavaScript loader into repositories...
Le payload malveillant est fragmenté en Base64 dans des commentaires HTML insérés dans chaque fichier SVG de drapeaux... Un fichier JavaScript ( serverValidation.js ) réassemble ces fragments... puis les exécute via eval().
The payload hides in config files, fake .woff2 font files, and .vscode/tasks.json triggers... one or more of those fonts is actually malicious JavaScript.
Le processus se masque sous le nom npm-cache .
The appropriate command downloads and executes a script from the command-and-control (C&C) server... uploads the information to hxxp://66.235.175[.]117:1244/uploads.
For FTP uploads, the C&C server provides the domain, username, and password.
The payload hides in config files... then uses blockchain dead-drops to download the Lazarus stealer toolkit.
Clipboard stealer / Windows PE dropper : ... téléchargement de binaires secondaires ( hostService.exe , printSvc.exe , dhcpSvc.exe ) depuis file.rightwidth[.]dev .
345 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
171 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a loader tool associated with the malware/tooling discussed in the Contagious Interview campaign.
Referenced as a related developer-targeting malware family previously used in fake-project delivery chains.
BeaverTail3
A Lazarus-associated loader used as part of the PolinRider infection chain to fingerprint the host OS and bootstrap follow-on implants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.