OtterCookie is a JavaScript-based malware family associated with the DPRK-linked Contagious Interview campaign and linked by multiple researchers to Lazarus-aligned activity, including clusters tracked as WaterPlum, Famous Chollima, PurpleBravo, and REF9403. First observed in 2024 and subsequently updated through multiple versions, it evolved from an initially simple file-grabbing implant into a modular cross-platform stealer and backdoor toolkit targeting developer and cryptocurrency-centric environments.
OtterCookie has been delivered through several social-engineering and supply-chain mechanisms. Observed vectors include fake recruiter and coding-test lures, trojanized repositories, malicious VS Code task configurations that execute when a project is opened, npm package compromise, and staged payload delivery hidden inside benign-looking assets such as SVG image files or fake font resources. In developer-focused intrusions, repositories often remain functional while concealed JavaScript reconstructs and executes the malware when the local server starts, reducing suspicion and increasing the likelihood of compromise.
Functionally, OtterCookie supports browser credential theft, cryptocurrency wallet data theft, bulk file collection, clipboard theft, and remote command execution. Later variants added hardcoded file-exfiltration logic, Windows support, virtual-environment checks, and dedicated stealer modules. Reported targets include credentials and data from Chromium-based browsers, wallet extensions, MetaMask, Brave, Google Chrome, and macOS credential stores. Some variants use DPAPI to decrypt Chrome-stored credentials on Windows, while others collect browser and wallet artifacts without decryption. File-theft modules search for documents, images, source code, keys, configuration files, shell histories, cloud and SSH material, and other sensitive developer data. Clipboard-monitoring functionality is used to capture copied secrets and, in some campaigns, to support theft of cryptocurrency-related data.
OtterCookie also includes a remote-access component, commonly implemented with Socket.IO-based command-and-control, enabling operators to maintain interactive access and execute shell commands on compromised hosts. Some observed chains split functionality into separate scripts or modules for browser theft, file upload, and socket communications, and certain Windows-focused deployments additionally downloaded and launched secondary executables. The malware frequently uses obfuscation, staged delivery, runtime decoding, eval-based execution, anti-tamper logic, and environment checks to hinder analysis and evade static detection.
The malware primarily targets Windows, macOS, and Linux systems, with a strong emphasis on software developers, Web3 users, cryptocurrency operators, and organizations whose developer workstations may contain source code, browser sessions, cloud credentials, SSH keys, wallet extensions, and other high-value secrets. OtterCookie’s role in developer compromise also creates downstream supply-chain risk when infected users push trojanized code or expose access to broader organizational environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Contagious Interview campaign conducted by the Lazarus Group continues to expand its capabilities. We have observed an exponential evolution in the delivery mechanisms for the campaign’s main payloads: BeaverTail, InvisibleFerret, and OtterCookie.
We named it "OtterCookie" and published a blog article in December 2024... In OtterCookie v4, which has been observed since April 2025, two new Stealer modules have been added, and some new features have been added to the Main module.
Any user who ran the project ended up with a four-stage payload aligned with OTTERCOOKIE: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign used the JavaScript infostealer BeaverTail, the cross-platform Python backdoor InvisibleFerret, and most recently OtterCookie, a new backdoor identified in December 2024.
The campaign targeted Web3 and decentralised finance (DeFi) developers globally via AI-generated fake job offers delivered through LinkedIn, using three interoperating malware families BeaverTail, OtterCookie, and InvisibleFerret in a phased infection chain that begins with a malicious coding assessment and culminates in full credential exfiltration and wallet drainage.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
On 4 September 2025, npm user pavlo123123 (pavlovainerman[@]gmail.com) uploaded some-promise, a package that derives code from the legitimate any-promise package. some-promise comes loaded with a malicious postinstall script...
A helper script rebuilds the code and runs it at server start... Watch Node processes that spawn shells or PowerShell.
After the request, the flow code captures the request’s response, stores it in the token object, and executes the content using the eval() function.
the developers took care to split the entire URL into several parts within the code.
Attackers split the payload into Base64 chunks. Then they tucked those chunks inside SVG country-flag files. A helper script rebuilds the code and runs it at server start.
developers should review server startup files and asset directories, and look closely for dynamic code execution such as eval() or code that reads image files.
The recovered toolkit has four main parts: a browser credential and cryptocurrency-wallet stealer, a file stealer, a clipboard collector, and a remote-access component using Socket.IO.
The Stealer module run at first steals passwords and usernames stored in Google Chrome.
The Stealer module run at first steals passwords and usernames stored in Google Chrome.
the group’s developers created and implemented a code snippet that performs a POST request to an external address named fashdefi[.]store using port 6168.
162 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
109 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as malware hidden in SVG images to backdoor developers.
A multi-component malware package delivered via trojanized coding-test repositories in the Contagious Interview campaign. It steals browser credentials, crypto wallet data, developer files such as keys/configs/source code, includes a Socket.IO backdoor for live shell access, and monitors the clipboard for copied secrets across Windows, macOS, and Linux.
Malware hidden in SVG image assets within a fake coding-test project. When the server starts, a JavaScript loader reconstructs and executes the payload. The toolkit includes a browser credential and cryptocurrency-wallet stealer, a file stealer, a clipboard collector, and a Socket.IO-based remote access component for command execution.
A malware payload delivered in a four-stage Contagious Interview infection chain used against software developers via fake job postings and malicious coding challenges.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.