OmniStealer is a Python-based information stealer associated with DPRK-linked developer-targeting operations, particularly the PolinRider and broader Contagious Interview activity clusters. It has been delivered alongside DEV#POPPER and other Lazarus-linked tooling through software supply-chain compromises, weaponized repositories, fake interview lures, malicious developer projects, poisoned packages, and compromised maintainer accounts across ecosystems including npm, Go modules, and Packagist. Observed delivery chains commonly use obfuscated JavaScript or Node.js loaders that retrieve encrypted follow-on payloads from blockchain-backed dead-drop infrastructure spanning TRON, Aptos, and BNB Smart Chain, then decrypt and execute the stealer or provision Python to run it.
OmniStealer is designed for broad theft from developer workstations and cryptocurrency-focused targets. Reported collection includes host and environment information, browser credentials and data, cookies, wallet-extension data, standalone wallet material, password-manager data, Git credentials, GitHub CLI data, GitHub Desktop artifacts, Visual Studio Code storage, Windows Credential Manager data, Linux Secret Service data, and other development secrets. Multiple reports also associate it with browser-data theft, crypto-wallet exfiltration, and keylogging. The malware has been observed as part of multi-stage infections that maintain persistence through detached background processes and developer-tool compromise, while companion payloads such as DEV#POPPER provide remote access and additional post-exploitation capability.
The malware is closely tied to campaigns targeting software developers, open-source maintainers, and cryptocurrency organizations. Tradecraft overlaps with Famous Chollima, Void Dokkaebi, and Lazarus-linked operations, and the activity has been assessed as North Korea-aligned by multiple researchers. OmniStealer’s role in these intrusions is primarily data theft and exfiltration from compromised developer environments, enabling theft of credentials, source-access secrets, and cryptocurrency assets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
Peut provisionner Python et télécharger un infostealer Python (82 457 octets) identifié comme probable itération d’ OmniStealer.
The decrypted payloads then deploy remote access malware, including DEV#POPPER RAT and OmniStealer, to exfiltrate data from the compromised systems.
In prior reports using the same blockchain-C2 infrastructure and overlapping wallet addresses, the loader ultimately delivered DPRK-linked malware including DEV#POPPER RAT, OmniStealer, and BeaverTail-family payloads.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
"PolinRider Caused Dozens of npm and Go Compromises" ... #SupplyChain, #GitHub, #NPM, #InvisibleFerret, #OmniStealer, #PolinRider
DPRK’s goal is to compromise developer machines and accounts to silently propagate malicious code, clone repositories, and push backdoored commits without active human intervention.
T1195.002 — Compromise Software Supply Chain (Initial Access)
The bootstrap. The malware installs Node dependencies and a portable Python interpreter... The stealer. A reversed-base64, zlib-wrapped Python infostealer harvests browser credentials, crypto wallets, password managers, developer tool configs, and OS keystores
the payload dropped into each module is DPRK's obfuscated JavaScript loader. It resolves a second-stage payload from blockchain RPC infrastructure ... decrypts it with an embedded XOR key, and executes it with eval()
The code itself is so well obfuscated... String shuffling function... Array-based string obfuscation... Multi-layer encoding: Hex → Buffer → UTF8 → Reversed → XOR decryption.
public/fonts/fa-solid-400.woff2 isn't a font. It's JavaScript that reads XOR-encrypted payloads from on-chain transactions
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
A committed .vscode/tasks.json with runOptions.runOn: 'folderOpen' executes the moment the project folder opens in VS Code, Cursor, Antigravity, or GitHub Desktop, bypassing npm v12's lifecycle-script protections entirely.
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
This includes cryptocurrency wallets, private keys, browser credentials... The code systematically harvests credentials from Chrome, Edge, Brave, Firefox...
InvisibleFerret implant (also reported as DEV#POPPER RAT and OmniStealer) for credential theft, browser-data theft, wallet exfiltration, and socket.io-based C2.
It sends a Windows Chrome user agent and the header Sec-V: A9-0135-3 in a request to /$/boot . It XOR-decrypts the response using ThZG+0jfXE6VAGOJ and calls eval() on the result.
42 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python infostealer component used in the PolinRider infection chain to harvest credentials, browser data, crypto wallets, password managers, developer tool configs, and OS keystores, with exfiltration over HTTP C2 and Telegram.
Named malware mentioned in connection with the post, likely a stealer based on its name, but only referenced as a hashtag here.
A Python infostealer assessed as related to the detached payload branch. It harvests environment and host information, credential stores, browser data, browser extension storage for wallets and password managers, Git credentials, GitHub configuration and logs, and Visual Studio Code storage.
Infostealer Python téléchargé par la branche détachée du chargeur, décrit comme une probable itération d’OmniStealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.