Chessfi is a trojanized Node.js application used in a Contagious Interview / Deceptive Development campaign attributed by Cisco Talos to Famous Chollima, a DPRK-aligned subgroup of Lazarus. It was presented as part of a fake job or development task and hosted on Bitbucket at hxxps[://]bitbucket[.]org/dev-chess/chess-frontend[.]git. Talos assessed a victim was likely deceived by a fake job offer and installed Chessfi, with delivery possibly occurring via platforms such as Fiverr or through Discord-shared repositories.
The infection chain relied on a malicious npm dependency, "node-nvm-ssh," hosted on the official NPM repository. When the victim ran "npm install," postinstall scripts executed obfuscated JavaScript through package.json logic that invoked "npm run skip," loaded test/fixtures/eval/index.js, and ultimately read and eval'd a file named "test.list." Talos reported that test.list was over 100 KB and obfuscated with Obfuscator.io.
The final payload exhibited combined BeaverTail and OtterCookie characteristics, reflecting Talos' assessment that the distinction between those toolsets is increasingly blurred. Observed capabilities included theft of cryptocurrency-related data and credentials, keylogging, screenshot capture, optional clipboard monitoring, remote shell access, filesystem traversal and file exfiltration, and targeting of cryptocurrency browser extensions in Chrome and Brave. The keylogging module used node-global-key-listener for keystroke capture, screenshot-desktop for screenshots, and sharp for image conversion. It stored keystrokes as "1.tmp" and screenshots as "2.jpeg" in a temporary "windows-cache" folder, flushing keystrokes every second and capturing screenshots every four seconds.
Associated attacker infrastructure included hxxp[://]172[.]86[.]88[.]188:1478/upload for keylog and screenshot uploads, hxxp[://]172[.]86[.]88[.]188:1418/socket[.]io/ for remote shell communications via socket.io-client, hxxp[://]172[.]86[.]88[.]188/api/service/makelog for logging and clipboard-related exfiltration, hxxp[://]172[.]86[.]88[.]188:1476/upload for file uploads, and hxxp[://]138[.]201[.]50[.]5:5961/upload for exfiltration of cryptocurrency browser extension and browser data. File theft logic targeted terms such as wallet, seed, mnemonic, phrase, and credential, as well as files including .docx, .pdf, .txt, .json, .js, and .ts.
High-confidence targeting reflected in the reporting includes job seekers, software developers, and users in cryptocurrency/Web3-related contexts. Talos observed one infection in an organization headquartered in Sri Lanka but assessed the organization itself was likely not the intended target; rather, the compromise stemmed from an individual installing the trojanized Chessfi application.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ChessFi is a legitimate-looking Node.js application that has been trojanized to deliver malware, targeting users in the cryptocurrency and developer communities.
Trojanized Node.js/Web3 chess application used as a lure in a fake job interview process; installing it pulls a malicious npm dependency and ultimately executes an obfuscated final payload that includes BeaverTail and OtterCookie functionality for data theft and remote access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.