OtterCookie Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
November 17, 2025
Last Seen
July 20, 2026

OtterCookie is a malware family tracked across 7 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 17, 2025; most recent activity July 20, 2026.

Overview

OtterCookie is a malware family attributed to North Korean threat actors. Recent campaigns show updated OtterCookie variants being spread through popular developer ecosystems, including npm packages and hosting platforms like GitHub and Vercel, highlighting a cross-platform supply-chain approach and expanding distribution; the activity underscores the threat actors' evolving infrastructure to disseminate credential/cookie-stealing malware.

Related Threat Clusters

Recent Intelligence Reports

  • Contagious Interview Malware Svg Steganography — www.elastic.co · July 20, 2026
  • Fake Coding Tests Deliver OtterCookie — Thehackernews · July 17, 2026
  • Slow Fog: HexagonalRodent is targeting Web3 developers with attacks — Chaincatcher · April 25, 2026
  • SlowMist Warns of Lazarus Group's Social Engineering Attacks on Web3 Developers — Kucoin · April 24, 2026
  • Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories — Trendmicro · April 22, 2026
  • WaterPlum Unleashes “StoatWaffle” Malware in VSCode Supply Chain Attack — Gbhackers · March 19, 2026
  • North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware — Thehackernews · November 28, 2025
  • North Korean Hackers Abuse npm, GitHub, and Vercel to Spread OtterCookie Malware — Gbhackers · November 27, 2025

CVSS v3.1 Breakdown