BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean Hackers Flood npm with 197 Malicious Packages

North Korean Hackers Deploy 197 Malicious npm Packages Spreading OtterCookie Malware Through Fake Job Recruitment and Phishing Campaigns

  • North Korean Hackers have released 197 malicious packages on the npm registry since last month.
  • These packages spread a variant of OtterCookie Malware that can steal sensitive data and provide remote control of infected machines.
  • The malware avoids detection by Sandbox systems and targets browser credentials, cryptocurrency wallets, and system information.
  • The attack uses fake job recruitment tactics and staged coding tasks to lure victims.
  • A separate campaign delivers GolangGhost malware through fraudulent camera or microphone fix websites and fake Chrome prompts.

North Korean threat actors behind the Contagious Interview campaign have deployed 197 new malicious packages on the npm registry since last month. These packages have been downloaded over 31,000 times and deliver a malware variant called OtterCookie, combining features from BeaverTail and earlier OtterCookie versions, according to Korea-contagious-interview-npm-attacks” target=”_blank” rel=”noopener”>Socket.

- Advertisement -

Some of the identified malicious “loader” packages include bcryptjs-node, cross-sessions, json-oauth, node-tailwind, react-adparser, session-keeper, tailwind-magic, tailwindcss-forms, and webpack-loadcss. The malware evades sandbox and virtual machine detection, profiles the infected system, and establishes a command-and-control (C2) channel. This channel grants attackers remote shell access and capabilities to steal clipboard contents, log keystrokes, capture screenshots, and collect browser credentials, documents, cryptocurrency wallet data, and seed phrases.

Earlier reports by Cisco Talos noted the convergence of OtterCookie and BeaverTail features after an infection that affected a system linked to an organization in Sri Lanka. The infection appeared to result from a user running a Node.js application during a fake job interview process.

Analysis shows the malware connects to a hard-coded Vercel URL (“tetrismic.vercel[.]app”), which fetches the OtterCookie payload from a GitHub repository controlled by the threat actors. The related GitHub account, stardev0914, has since been disabled. Security researcher Kirill Boychenko commented on the campaign’s intensity, noting how North Korean hackers have tailored their tools to modern JavaScript and crypto development environments.

Separately, threat actors operating under the ClickFake Interview moniker have used fake assessment websites resembling camera or microphone troubleshooting guides to distribute malware known as GolangGhost (also called FlexibleFerret or WeaselStore). This malware, written in Go, contacts a fixed C2 server to gather system data, upload and download files, execute commands, and extract information from Google Chrome. It achieves persistence by installing a macOS LaunchAgent that runs a shell script at user login.

- Advertisement -

The attack chain also includes a decoy app displaying a fake Chrome camera access prompt, followed by a Chrome-style password prompt to capture and send passwords to a Dropbox account. As stated by Validin, this campaign targets individuals through fraudulent hiring processes, including fake coding exercises and recruitment platforms, differentiating it from other North Korean schemes that embed agents in legitimate businesses. More information on this is available here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Dmail Network Shuts Down After Five-Year Decentralized Run

Decentralized email platform Dmail Network will officially begin ceasing its services on May 15...

Bank of Canada Study: Aave V3 Had Zero Bad Loans in 2024

A Bank of Canada staff analysis found Aave V3 had zero non-performing loans in...

Tech Giants Found AI Payment Protocol Group

The x402 Foundation launched on Thursday by the Linux Foundation to govern an AI...

Elliptic Links $286M Drift Protocol Hack to North Korea

Elliptic attributes the $286 million exploit of Drift Protocol to actors linked to North...

Coinbase Wins Trust Charter, Won’t Become A Bank

Coinbase received conditional approval from the U.S. Office of the Comptroller of the Currency...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading