Malicious Node Package Deploys OtterCookie

2025-10-06 Blackpoint Cyber

https://blackpointcyber.com/blog/malicious-node-package-deploys-ottercookie/

Thumbnail for Malicious Node Package Deploys OtterCookie

Blackpoint SOC analyzed a North Korea-linked OtterCookie intrusion delivered through a trojanized Bitbucket repository posing as a 3D chess project. The loader deliberately triggers an initialization error, fetches JavaScript from serve-cookie[.]vercel[.]app, and executes the returned code to install a malicious Node-based client-app under a fake user-writable System32 path. Persistence is maintained through svchost.bat, svchost.ps1, and a WindowsUpdate Run key, while .sysupdater.dat provides obfuscated clipboard collection, screenshot capture, C2 logging, and command staging. The operators also deployed simple-keyboard-monitor.ps1 for keystroke capture, giving them continuous visibility into developer or financial-sector victim activity and a path to credential theft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 86.106.85.234 2025-10-06 2026-02-03
HASH adee6c5cc15432f0e4a5202b2653aeb… 2025-10-06 2025-10-06
HASH 8b3deb9426b405eb8e08ac2a9868e55… 2025-10-06 2025-10-06
HASH c0cec1ca432eb8ae0cb43325ca10c25… 2025-10-06 2025-10-06
HASH 57533e0bf2a9857bf1e603039b6b3e9… 2025-10-06 2025-10-06
HASH 8d3b4d38914029c2b9cf83f6ded99fa… 2025-10-06 2025-10-06
HASH c077f24e0c8fd9b10af046f7811046b… 2025-10-06 2025-10-06
HASH 51322339b720d6e81bef2b7d415c242… 2025-10-06 2025-10-06
IPv4 146.70.87.202 2025-10-06 2025-10-06
IPv4 86.106.85.90 2025-10-06 2025-10-06
IPv4 193.27.14.208 2025-10-06 2025-10-06
IPv4 193.187.148.116 2025-10-06 2025-10-06
IPv4 78.46.94.230 2025-10-06 2025-10-06

Related Reports

« Back