BeaverTail is a JavaScript-based information stealer and downloader used in the North Korea-linked Contagious Interview campaign, associated with actors tracked as Famous Chollima, UNC5342, and WaterPlum. It targets Windows, macOS, and Linux systems, particularly those belonging to software developers and cryptocurrency, blockchain, and Web3 professionals. Operators conceal it within apparently legitimate Node.js projects, malicious npm packages, and coding-assessment repositories. Fraudulent recruiters persuade job candidates to download and execute these projects during technical interviews or assignments.
BeaverTail collects browser credentials and cryptocurrency-wallet extension data, including data associated with MetaMask, Coinbase Wallet, Phantom, and other wallets. Its collection routines target Chromium-based browser profiles, macOS keychain files, Linux keyring data, Firefox data, and Solana wallet key material. It gathers host and operating-system information and exfiltrates collected files through HTTP POST requests. Obfuscated JavaScript and code concealed after extensive whitespace hinder inspection. An analyzed implementation repeats its collection workflow five additional times at ten-minute intervals.
After collecting sensitive data, BeaverTail downloads and executes InvisibleFerret, a Python-based second-stage backdoor. On Windows, it can retrieve a portable Python runtime when necessary; on macOS and Linux, it invokes Python 3. This combination provides an initial information-theft stage and a mechanism for deploying follow-on malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This document delves into the intricacies of the "BeaverTail" dropper, the Node.js component, responsible for downloading and executing a secondary Python-based payload (named “InvisibleFerret”) after stealing sensitive data from the victim’s computer.
BeaverTail JavaScript-based malware delivered through malicious packages and developer projects
The PolinRider threat group was first detected this year when cybersecurity analysts identified hundreds of GitHub repositories with hidden JavaScript code that downloads an updated version of the BeaverTail malware.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
BeaverTail malware begins by executing its “main” function, gathering system information to determine if the system runs Windows, macOS, or Linux.
414 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family distributed by the North Korean-linked WaterPlum campaign through fraudulent technical interviews and developer-task lures.
A named malicious payload delivered through trojanized NPM packages in WaterPlum's fake-job-interview campaign. The content attributes credential, cryptocurrency-wallet, and other data theft to the campaign, but does not separately specify BeaverTail's individual capabilities.
A malware family delivered through fake technical-interview downloads in the WaterPlum/Contagious Interview campaign. The payload set steals browser and cryptocurrency-wallet credentials and other sensitive data, and can support follow-on access.
The post links to Atlassian's "Disrupting Contagious Interview" publication and tags #BeaverTail alongside other malware names.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.