Malicious Node Package Deploys OtterCookie
2025-10-06 • Blackpoint Cyber •
https://blackpointcyber.com/blog/malicious-node-package-deploys-ottercookie/
Blackpoint SOC analyzed a North Korea-linked OtterCookie intrusion delivered through a trojanized Bitbucket repository posing as a 3D chess project. The loader deliberately triggers an initialization error, fetches JavaScript from serve-cookie[.]vercel[.]app, and executes the returned code to install a malicious Node-based client-app under a fake user-writable System32 path. Persistence is maintained through svchost.bat, svchost.ps1, and a WindowsUpdate Run key, while .sysupdater.dat provides obfuscated clipboard collection, screenshot capture, C2 logging, and command staging. The operators also deployed simple-keyboard-monitor.ps1 for keystroke capture, giving them continuous visibility into developer or financial-sector victim activity and a path to credential theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 86.106.85.234 | 2025-10-06 | 2026-02-03 |
| HASH | adee6c5cc15432f0e4a5202b2653aeb… | 2025-10-06 | 2025-10-06 |
| HASH | 8b3deb9426b405eb8e08ac2a9868e55… | 2025-10-06 | 2025-10-06 |
| HASH | c0cec1ca432eb8ae0cb43325ca10c25… | 2025-10-06 | 2025-10-06 |
| HASH | 57533e0bf2a9857bf1e603039b6b3e9… | 2025-10-06 | 2025-10-06 |
| HASH | 8d3b4d38914029c2b9cf83f6ded99fa… | 2025-10-06 | 2025-10-06 |
| HASH | c077f24e0c8fd9b10af046f7811046b… | 2025-10-06 | 2025-10-06 |
| HASH | 51322339b720d6e81bef2b7d415c242… | 2025-10-06 | 2025-10-06 |
| IPv4 | 146.70.87.202 | 2025-10-06 | 2025-10-06 |
| IPv4 | 86.106.85.90 | 2025-10-06 | 2025-10-06 |
| IPv4 | 193.27.14.208 | 2025-10-06 | 2025-10-06 |
| IPv4 | 193.187.148.116 | 2025-10-06 | 2025-10-06 |
| IPv4 | 78.46.94.230 | 2025-10-06 | 2025-10-06 |