OmniStealer is a Python-based, cross-platform information stealer associated with DPRK-linked developer-targeting activity, including the Contagious Interview and PolinRider campaigns. It is commonly delivered as a follow-on payload by JavaScript or Node.js loaders embedded in weaponized code repositories, trojanized open-source packages, and fake coding assignments distributed through fraudulent recruitment lures. OmniStealer targets Windows, macOS, and Linux systems, particularly developer workstations and cryptocurrency-sector targets. It harvests browser data, browser cookies, credentials, password-manager data, cryptocurrency wallet applications and extensions, cloud-storage credentials, Git and GitHub credentials, IDE-related data, and other developer secrets. Reported variants target more than 150 cryptocurrency wallets. Stolen information may be exfiltrated over HTTP or through messaging-bot services. OmniStealer has been deployed alongside DEV#POPPER and other tooling in supply-chain compromises affecting npm, Go, Packagist, and compromised source-code repositories.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OmniStealer is a 3,500-line Python credential harvester targeting browsers, crypto wallets, password managers, and cloud storage across Windows, macOS, and Linux.
“Access to lsass is observed, and a second YARA rule fires for an XFiles and OmniStealer style information stealer.”
“Access to lsass is observed, and a second YARA rule fires for an XFiles and OmniStealer style information stealer.”
the first Python Downloader ( Payload1_2 (HTTP Payload Stager) ) which ultimately leads to downloading the OmniStealer malware as discussed in Part 2
The decrypted payloads then deploy remote access malware, including DEV#POPPER RAT and OmniStealer, to exfiltrate data from the compromised systems.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
“Victim receives a fake job offer via Telegram, pointing to a GitHub repo or trojanized NPM package.”
DPRK’s goal is to compromise developer machines and accounts to silently propagate malicious code, clone repositories, and push backdoored commits without active human intervention.
T1195.002 — Compromise Software Supply Chain (Initial Access)
“[The HTTP stager] acted as a Python dropper: it installed Python silently on the victim's machine, then used it to fetch ... the OmniStealer payload.”
“The initial loader checks transactions on TRON ... to locate encrypted JavaScript stored in BNB Smart Chain transactions.”
public/fonts/fa-solid-400.woff2 isn't a font. It's JavaScript that reads XOR-encrypted payloads from on-chain transactions
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
“Access to lsass is observed, and a second YARA rule fires for an XFiles and OmniStealer style information stealer.”
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
“A separate one-time stealer seeks browser information, password manager data, cloud storage credentials and cryptocurrency wallet material.”
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
novel tradecraft such as Cross-Chain TxDataHiding techniques combined with the subsequent creation of a takedown-proof Command and control (C2) infrastructure
a multi-layered attack leveraging novel blockchain-based command-and-control infrastructure
“C2 path /init Port 443 endpoint returning the RAT and scanner” and “C2 path /boot Port 443 Ethereum recovery endpoint.”
57 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential and cryptocurrency-wallet stealer delivered within the XCTDH infection chain. It targets browser data, password-manager data, cloud credentials, and material from 153 cryptocurrency wallets; stolen data is exfiltrated through a messaging-bot interface.
Post links to "XCTDH Adopts Hash Hiding" and includes the hashtag #OmniStealer.
Python-based, one-shot credential harvester. It targets more than 60 wallet extensions, browser data, password managers, and cloud-storage data; the campaign's dropper silently installs Python to execute it, and it exfiltrates collected data through Telegram.
Information-stealer component or detection profile associated with credential theft, including observed LSASS access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.