OtterCookie Expands Targeting to AI Coding Tools

2026-04-04 Cyber And Ramen

https://cyberandramen.net/2026/04/04/ottercookie-expands-targeting-to-ai-coding-tools-analysis-of-a-trojanized-npm-campaign/

Thumbnail for OtterCookie Expands Targeting to AI Coding Tools

A malicious npm account, gemini-check, published gemini-ai-checker as a fake Google Gemini token verifier and used related packages express-flowlimit and chai-extensions-extras that shared the same Vercel staging infrastructure. The package assembled a request to server-check-genimi.vercel[.]app/defy/v3 with a bearer-style token and executed returned JavaScript in memory through Function.constructor. De-obfuscated payloads showed a four-module Node.js backdoor consistent with OtterCookie activity associated with the DPRK-linked Contagious Interview campaign, including Socket.IO remote control, credential theft, file exfiltration, and clipboard monitoring. The malware communicated with 216.126.237[.]71 on ports 4891, 4896, 4899, and 80, and explicitly searched developer and AI coding tool directories such as .cursor, .claude, .gemini, .windsurf, .pearai, and .eigent for tokens, keys, conversations, and source code.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 216.126.237.71 2026-04-02 2026-04-24
HASH d26da2d0f14d8a160f2f937a6081dae… 2026-04-04 2026-04-04

Related Reports

« Back