OmniStealer is a Python-based information stealer associated with North Korea-linked developer-targeting intrusion activity, particularly the PolinRider and Contagious Interview clusters and tooling overlaps involving DEV#POPPER and BeaverTail. It has been deployed in software supply-chain compromises, weaponized repositories, and malicious package ecosystems affecting npm, Go modules, Packagist, and compromised GitHub projects, as well as in socially engineered developer lures tied to fake interview or collaboration scenarios.
The malware is designed for broad theft of valuable host and user data. Reported collection targets include browser credentials and stored data from Chromium- and Firefox-based browsers, cryptocurrency wallet extensions and standalone wallet applications, password-manager data, development secrets, Git credentials, GitHub CLI data, IDE and editor storage, GitHub Desktop artifacts, environment and host information, and in some reporting Windows Credential Manager and Linux Secret Service data. Multiple reports also associate OmniStealer with keylogging and large-scale exfiltration of cryptocurrency-related material and developer secrets.
Observed delivery chains commonly use obfuscated JavaScript or Node.js loaders that retrieve encrypted payloads from blockchain-backed dead-drop infrastructure spanning TRON, Aptos, and BNB Smart Chain, often with fallback HTTP retrieval. In several campaigns, a JavaScript implant or loader executed at import time or through developer tooling, then provisioned Python if necessary and downloaded OmniStealer as a later-stage payload. This tradecraft has been observed in compromised npm packages, malicious VS Code task-based execution chains, weaponized repositories, and broader supply-chain compromises of legitimate maintainer accounts or developer environments.
OmniStealer has been linked to campaigns targeting software developers and cryptocurrency-focused victims, with the broader operations assessed as likely DPRK-affiliated. The malware is typically deployed alongside DEV#POPPER, which provides remote access and persistence, while OmniStealer focuses on harvesting and exfiltrating credentials, browser data, wallet information, and other sensitive artifacts from Windows, macOS, and Linux systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
the first Python Downloader ( Payload1_2 (HTTP Payload Stager) ) which ultimately leads to downloading the OmniStealer malware as discussed in Part 2
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
Peut provisionner Python et télécharger un infostealer Python (82 457 octets) identifié comme probable itération d’ OmniStealer.
The decrypted payloads then deploy remote access malware, including DEV#POPPER RAT and OmniStealer, to exfiltrate data from the compromised systems.
In prior reports using the same blockchain-C2 infrastructure and overlapping wallet addresses, the loader ultimately delivered DPRK-linked malware including DEV#POPPER RAT, OmniStealer, and BeaverTail-family payloads.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
"PolinRider Caused Dozens of npm and Go Compromises" ... #SupplyChain, #GitHub, #NPM, #InvisibleFerret, #OmniStealer, #PolinRider
DPRK’s goal is to compromise developer machines and accounts to silently propagate malicious code, clone repositories, and push backdoored commits without active human intervention.
T1195.002 — Compromise Software Supply Chain (Initial Access)
The bootstrap. The malware installs Node dependencies and a portable Python interpreter... The stealer. A reversed-base64, zlib-wrapped Python infostealer harvests browser credentials, crypto wallets, password managers, developer tool configs, and OS keystores
the payload dropped into each module is DPRK's obfuscated JavaScript loader. It resolves a second-stage payload from blockchain RPC infrastructure ... decrypts it with an embedded XOR key, and executes it with eval()
The code itself is so well obfuscated... String shuffling function... Array-based string obfuscation... Multi-layer encoding: Hex → Buffer → UTF8 → Reversed → XOR decryption.
public/fonts/fa-solid-400.woff2 isn't a font. It's JavaScript that reads XOR-encrypted payloads from on-chain transactions
temp_auto_push.bat , the script behind the GitHub and Go compromises, runs locally on the infected machine using the developer's own already-authorized git credentials.
A committed .vscode/tasks.json with runOptions.runOn: 'folderOpen' executes the moment the project folder opens in VS Code, Cursor, Antigravity, or GitHub Desktop, bypassing npm v12's lifecycle-script protections entirely.
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
The follow-on payloads are the familiar Lazarus toolkit: DEV#POPPER, OmniStealer, and InvisibleFerret, covering credential theft, browser-data theft, crypto-wallet exfiltration, and keylogging.
This includes cryptocurrency wallets, private keys, browser credentials... The code systematically harvests credentials from Chrome, Edge, Brave, Firefox...
novel tradecraft such as Cross-Chain TxDataHiding techniques combined with the subsequent creation of a takedown-proof Command and control (C2) infrastructure
a multi-layered attack leveraging novel blockchain-based command-and-control infrastructure
It sends a Windows Chrome user agent and the header Sec-V: A9-0135-3 in a request to /$/boot . It XOR-decrypts the response using ThZG+0jfXE6VAGOJ and calls eval() on the result.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python infostealer component used in the PolinRider infection chain to harvest credentials, browser data, crypto wallets, password managers, developer tool configs, and OS keystores, with exfiltration over HTTP C2 and Telegram.
Named malware mentioned in connection with the post, likely a stealer based on its name, but only referenced as a hashtag here.
A Python infostealer assessed as related to the detached payload branch. It harvests environment and host information, credential stores, browser data, browser extension storage for wallets and password managers, Git credentials, GitHub configuration and logs, and Visual Studio Code storage.
Infostealer Python téléchargé par la branche détachée du chargeur, décrit comme une probable itération d’OmniStealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.