A malicious npm campaign used the account gemini-check to publish trojanized packages including gemini-ai-checker, express-flowlimit, and chai-extensions-extras, disguising them as legitimate developer utilities while delivering a staged JavaScript payload from Vercel-hosted infrastructure. Researchers linked the malware to OtterCookie, a modular Node.js backdoor associated with the DPRK-linked Contagious Interview activity cluster, citing overlaps in payload design, remote access capability, and data-theft behavior. The packages were downloaded more than 500 times in total, and while gemini-ai-checker was removed, the other packages were still available at the time of reporting.
The malware executed code in memory to reduce detection and then stole browser credentials, cryptocurrency wallets, files, clipboard contents, and developer secrets. It also explicitly targeted directories tied to AI coding tools including Cursor, Claude, Gemini CLI, Windsurf, PearAI, and Eigent, enabling theft of API tokens, conversation logs, source code, SSH keys, and cloud credentials. The campaign shows a software supply-chain intrusion aimed directly at developers, with a particular focus on compromising AI-assisted development environments and the sensitive access they contain.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
By the time of later reporting, the three malicious npm packages had accumulated more than 500 total downloads, indicating measurable exposure among developers.
Public reporting assessed the malicious npm campaign with moderate-high confidence as linked to the DPRK-associated Contagious Interview threat activity based on strong similarities to OtterCookie malware and shared tradecraft.
Researchers found the npm campaign delivered a multi-module backdoor closely resembling OtterCookie, capable of remote access, credential theft, file exfiltration, clipboard monitoring, and theft of data from AI coding tools including Cursor, Claude, Gemini CLI, Windsurf, PearAI, and Eigent.
By shortly before April 1, the gemini-ai-checker package had been taken down from npm, while the related packages express-flowlimit and chai-extensions-extras remained available.
The threat actor also operated the npm packages express-flowlimit and chai-extensions-extras, which used the same Vercel-hosted staging infrastructure to fetch and execute remote JavaScript payloads.
A malicious npm package named gemini-ai-checker was published under the account "gemini-check," posing as a Google Gemini token verification utility while delivering malware to developers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
infosec.pub
Open sourcecybersecuritynews.com
Open sourcecyberandramen.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.