OtterCookie is a North Korea-linked modular malware family associated with the Contagious Interview and related DeceptiveDevelopment activity clusters that target software developers, especially individuals and organizations connected to cryptocurrency projects. It emerged in late 2024 as a JavaScript-based evolution of earlier developer-focused theft tooling and has been repeatedly observed in fake recruiting and coding-assessment campaigns that deliver trojanized repositories, malicious npm packages, and editor workflow abuse. Reported lures include fraudulent recruiter outreach, fake job offers, coding tests, and malicious development projects that execute the malware when victims install dependencies, start local servers, or open repositories in development environments.
OtterCookie combines infostealing and remote-access functionality. Documented modules include browser credential theft, cryptocurrency wallet theft, recursive file collection, clipboard monitoring, and a Socket.IO-based command-and-control component that enables remote shell access and follow-on tasking. Observed variants target browser data from Chromium-based browsers across Windows, macOS, and Linux, and search for wallet extension data, saved credentials, autofill information, and other sensitive artifacts. File theft components have been reported to search for cloud credentials, SSH material, shell histories, environment files, source code, documents, and other developer-relevant secrets. Some reporting also attributes clipboard theft, keylogging, screenshot capture, active workspace monitoring, and Windows secondary payload delivery to OtterCookie-related samples or closely aligned payloads.
The malware commonly uses obfuscated JavaScript loaders and anti-analysis measures, including integrity checks, virtualization or sandbox awareness, staged payload reconstruction, and process masquerading. Multiple campaigns have hidden OtterCookie payload fragments inside benign-looking project assets such as SVG files or fake font files, then reassembled and executed them at runtime. OtterCookie has also been delivered through malicious VS Code task configurations and npm supply-chain activity. Its tradecraft is consistent with DPRK operations that seek cryptocurrency theft, credential harvesting, and potential downstream compromise of developer environments and software supply chains.
OtterCookie is widely linked to DPRK threat activity overlapping with Lazarus-associated clusters, including Contagious Interview, PurpleBravo, Famous Chollima, and DeceptiveDevelopment. Victims have included software developers, security researchers, AI engineers, and cryptocurrency-sector personnel. The malware’s combination of credential theft, wallet theft, file exfiltration, and interactive remote access makes it particularly dangerous on developer workstations, where browser sessions, cloud secrets, source code, signing material, and wallet assets may coexist.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
What lands is a four-part OtterCookie kit: a browser-and-wallet stealer, a file stealer, a Socket.IO remote-access trojan, a clipboard grabber, all delivered through fake coding-test “recruiter” lures.
Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer.
This will eventually to either Ottercookie / Beavertail malware. Running the entire repository ultimately leads to an infection.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Elastic said it discovered the campaign after the threat actors targeted members of its community Slack workspace with social engineering lures for purported job offers. | The messages, posted by a user named Maxwell on the #jobs Slack channel in late May 2026, sought an experienced developer to help with upgrading their e-commerce platform.
OtterCookie evolved from a basic tool for executing remote commands... and can execute shell commands.
SVG is text. Comments in it are legal syntax. So an antivirus engine that renders the flag or scans it pixel by pixel never reads the code sitting in the markup.
The operators chop their malware into pieces and tuck them inside the HTML comment blocks of SVG country-flag images, then let a victim’s own machine stitch the fragments back together and run them at server start.
attempted to download files disguised as text and rename them to executable names such as hostService.exe , printSvc.exe , and dhcpSvc.exe
What lands is a four-part OtterCookie kit: a browser-and-wallet stealer
Projects hide payloads with steganography in SVG image files... The payloads are split into Base64 fragments inside HTML comments across every SVG flag image inside an assets directory.
This third stage establishes a persistent Socket.IO command-and-control channel to the domain (controller.rightwidth[.]dev) over HTTPS.
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
98 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular malware kit used in North Korea-linked Contagious Interview activity, delivering browser and cryptocurrency wallet theft, file theft, remote access via Socket.IO, and clipboard theft through fake recruiter/coding-test lures.
Malware associated with the Contagious Interview campaign. In this reporting, the payload chain includes browser credential and crypto-wallet theft, file theft, persistent C2/RAT capability, clipboard theft, and secondary Windows PE download/execution. The article explicitly links the main payload by code similarity to OTTERCOOKIE.
A multi-function payload used in a DPRK-aligned fake job/coding test campaign. It steals browser credentials and crypto wallet data, exfiltrates files, provides remote access over a Socket.IO channel, monitors the clipboard, and may download additional Windows executables disguised as text files.
A cross-platform modular malware used in the Contagious Interview campaign that steals browser credentials and cryptocurrency wallet data, collects files by extension, captures clipboard contents, enables persistent Socket.IO-based remote access with shell command execution, can load additional modules, checks for VM environments, and can drop Windows executables.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.