Mapping Ottercookie Infrastructure

2026-04-07 Walmart

https://medium.com/walmartglobaltech/mapping-ottercookie-infrastructure-1c49f0cd3883

Thumbnail for Mapping Ottercookie Infrastructure

Jason Reaves links NodeJS stealer and backdoor infrastructure to activity resembling DPRK developer-targeting campaigns that use fake interviews or attacker-supplied code repositories. The excerpt shows an npm package, npm-doc-builder, executing a postinstall script that contacts cloudflareinsights[.]vercel[.]app, retrieves scan patterns for files such as .env and shell history, adds an SSH key on Linux, and uploads collected files. Additional code pivots expose obfuscated loader behavior and upload endpoints on 144.172.116[.]22 using ports 8085, 8086, 8087, and 17500. Censys banner and body-hash pivots identify related infrastructure across multiple 144.172.* and 107.189.* IP addresses, giving defenders network indicators for stealer activity associated with DPRK-style developer compromise.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 31d55cb5dd194cd99387d386e84d8b2… 2026-04-07 2026-04-07
HASH 3a08e7f236aac7f6eb6f75911b98bc5… 2026-04-07 2026-04-07
HASH 76df69b919642ab4d54a94e8988b4fa… 2026-04-07 2026-04-07
HASH 843ac01149cced785dfebd0028d3b03… 2026-04-07 2026-04-07
URL https://cloudflareinsights.verc… 2026-04-07 2026-04-07
URL https://cloudflareinsights.verc… 2026-04-07 2026-04-07
URL https://cloudflareinsights.verc… 2026-04-07 2026-04-07
IPv4 144.172.116.22 2026-04-07 2026-04-07
IPv4 144.172.110.228 2026-04-07 2026-04-07
IPv4 107.189.22.20 2026-04-07 2026-04-07
IPv4 144.172.93.169 2026-04-07 2026-04-07
IPv4 144.172.93.253 2026-04-07 2026-04-07
IPv4 144.172.110.96 2026-04-07 2026-04-07
IPv4 144.172.99.248 2026-04-07 2026-04-07
IPv4 144.172.99.81 2026-04-07 2026-04-07
IPv4 144.172.110.132 2026-04-03 2026-04-07

Related Reports

« Back