Jamf Threat Labs identified 14 unsigned, trojanized macOS DMG and PKG installers impersonating legitimate applications in the DPRK-attributed Contagious Interview campaign. The installers execute a hidden Intel-only .macos payload or abuse a malicious PKG preinstall chain, contact 162.0.239[.]85 for staged scripts, and deploy the OtterCookie malware family. Because the samples are unsigned and unnotarized, macOS Gatekeeper should block them unless a user removes the quarantine attribute.
OtterCookie provides Socket.IO-based remote access and can steal browser and cryptocurrency-wallet credentials, search memory for sensitive files, and capture clipboard contents. The activity extends the campaign beyond its prior developer-focused lures—including malicious VS Code tasks and Git hooks—while retaining related staging behavior; the updated chain uses ~/.task and JWT-protected requests to retrieve later-stage payloads.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
The lazarusholic Bluesky account linked to Jamf's analysis, characterizing the activity as trojanized macOS installers associated with Contagious Interview and OtterCookie.
Analysis of the GAPIUpdate.dmg macOS disk image detailed its execution chain and linked it to Odyssey Stealer command-and-control infrastructure. The analysis reported cryptocurrency-wallet address replacement behavior and identified 27 related DMG files hosted on GitHub.
Technical reporting disclosed the staged macOS execution chain used by the trojanized installers, including hidden .macos launchers, the ~/.task Node.js payload directory, tokenized retrieval endpoints, and OtterCookie deployment. It also identified staging and C2 infrastructure, associated domains, ports, payload hashes, and OtterCookie's browser- and cryptocurrency-credential theft, clipboard collection, and in-memory file scanning capabilities.
Jamf Threat Labs identified 14 unsigned DMG and PKG installers impersonating legitimate macOS applications in the DPRK-attributed Contagious Interview campaign. The installers use hidden payloads or malicious PKG scripts to retrieve staged components and ultimately deploy OtterCookie malware.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecyberaccord.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcebsky.app
Open sourcejamf.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.