Fake Developer Interviews Deliver Backdoors and Steal Credentials

Threat actors used fake developer hiring to push malicious NPM packages that install backdoors (OtterCookie, FlexibleFerret). The campaign targets developers at technology and media firms and steals API tokens, cloud credentials, crypto wallets, and source code. Block unvetted package installs

Part of the PlainSec briefing for 2026-03-15

Sources