Tracking an OtterCookie Infostealer Campaign Across npm
Reported 13 Apr 2026 by otx · Severity: medium
Between April 6-9, 2026, multiple obfuscated malicious npm packages were identified as variants of the OtterCookie infostealer attributed to North Korean threat actors. The campaign employs a two-layer distribution strategy where benign wrapper packages clone legitimate libraries