Mapping Ottercookie Infrastructure
2026-04-07 • Walmart •
https://medium.com/walmartglobaltech/mapping-ottercookie-infrastructure-1c49f0cd3883
Jason Reaves links NodeJS stealer and backdoor infrastructure to activity resembling DPRK developer-targeting campaigns that use fake interviews or attacker-supplied code repositories. The excerpt shows an npm package, npm-doc-builder, executing a postinstall script that contacts cloudflareinsights[.]vercel[.]app, retrieves scan patterns for files such as .env and shell history, adds an SSH key on Linux, and uploads collected files. Additional code pivots expose obfuscated loader behavior and upload endpoints on 144.172.116[.]22 using ports 8085, 8086, 8087, and 17500. Censys banner and body-hash pivots identify related infrastructure across multiple 144.172.* and 107.189.* IP addresses, giving defenders network indicators for stealer activity associated with DPRK-style developer compromise.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 31d55cb5dd194cd99387d386e84d8b2… | 2026-04-07 | 2026-04-07 |
| HASH | 3a08e7f236aac7f6eb6f75911b98bc5… | 2026-04-07 | 2026-04-07 |
| HASH | 76df69b919642ab4d54a94e8988b4fa… | 2026-04-07 | 2026-04-07 |
| HASH | 843ac01149cced785dfebd0028d3b03… | 2026-04-07 | 2026-04-07 |
| URL | https://cloudflareinsights.verc… | 2026-04-07 | 2026-04-07 |
| URL | https://cloudflareinsights.verc… | 2026-04-07 | 2026-04-07 |
| URL | https://cloudflareinsights.verc… | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.116.22 | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.110.228 | 2026-04-07 | 2026-04-07 |
| IPv4 | 107.189.22.20 | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.93.169 | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.93.253 | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.110.96 | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.99.248 | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.99.81 | 2026-04-07 | 2026-04-07 |
| IPv4 | 144.172.110.132 | 2026-04-03 | 2026-04-07 |