Threats · 188 days ago
Threat actors used fake developer hiring to push malicious NPM packages that install backdoors (OtterCookie, FlexibleFerret). The campaign targets developers at technology and media firms and steals API tokens, cloud credentials, crypto wallets, and source code. Block unvetted package installs
1 source covering this story
Threat actors pose as recruiters from crypto and AI companies and deliver backdoors such as OtterCookie and FlexibleFerret through fake coding assessments.
Part of the PlainSec briefing for 2026-03-15