Omnistealer: DPRK-Linked Blockchain-Based Infostealer Abusing TRON/Aptos/BSC as Resilient C2 to Loot Password Managers, Browser Credentials, Cloud Storage, and 60+ Crypto Wallets

Omnistealer: DPRK-Linked Blockchain-Based Infostealer (TL-2026-0360), also tracked as OmniStealer, is a high-severity malware campaign, first published 2026-04-14. It is linked to a North Korea-nexus actor with medium confidence, affects Google Chrome, maps to 24 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 45 indicators of compromise.

Key facts for TL-2026-0360

Threat ID
TL-2026-0360
Also known as
OmniStealer, Cross-Chain TxDataHiding, XCTDH, Omnistealer Crypto Heist
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-04-14
Last reviewed
2026-04-14
Attribution confidence
MEDIUM
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, software-development, cryptocurrency, defense, government, financial, food-delivery, adult-industry, freelance-platforms
Target regions
Global, North America, Europe, South Asia, South Korea, United States
Detection rules
9
Indicators of compromise
45

Malware and tooling in Omnistealer: DPRK-Linked Blockchain-Based Infostealer

Malware and tooling: Omnistealer, XCTDH loader, Aptos: 0x3414a658f13b652f24301e986f9e0079ef506992472c1d5224180340d8105837, Aptos: 0x3f0e5781d0855fb460661ac63257376db1941b2bb522499e4757ecb3ebd5dce3, Aptos: 0xbe037400670fbf1c32364f762975908dc43eeb38759263e7dfcdabc76380811e, BSC tx: 0xa8cdabea3616a6d43e0893322112f9dca05b7d2f88fd1b7370c33c79076216ff, BSC tx: 0xd33f78662df123adf2a178628980b605a0026c0d8c4f4e87e43e724cda258fef, BSC tx: 0xf46c86c886bbf9915f4841a8c27b38c519fe3ce54ba69c98d233d0ffc94d19fc, TRON: TLmj13VL4p6NQ7jpxz8d9uYY6FUKCYatSe, TRON: TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP, TRON: TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG

Omnistealer is an actively distributed, multi-stage infostealer tied to suspected DPRK-aligned operators who approach software developers with fake LinkedIn/Upwork job offers that drop malicious GitHub projects. The payload chain hides configuration and stage-routing data inside public transactions on TRON, Aptos, and Binance Smart Chain, then harvests credentials from 10+ password managers, 60+ browser crypto wallets, 9+ browsers, and major cloud-storage clients. Approximately 300,000 credentials have been collected across government, defense, financial, food-delivery, and adult-industry victims.

How Omnistealer: DPRK-Linked Blockchain-Based Infostealer works

Omnistealer (also tracked as the Cross-Chain TxDataHiding campaign) is a cross-platform JavaScript/Python infostealer and modular RAT first publicly documented by Malwarebytes Labs, Ransom-ISAC, and Dataconomy in late March and April 2026. The operation is being run through a fake-recruiter pipeline aimed primarily at freelance and full-stack developers: attackers pose as hiring managers on LinkedIn and Upwork, move candidates to Telegram or Discord, then send them a ''coding test'' hosted in a private GitHub repository. The trojanized project (most often a Tailwind/Next.js frontend such as github.com/isasmallbit/store-v) embeds a hostile Tailwind.config.js or next.config.mjs that runs on install.

The dropper is deliberately engineered for takedown resistance. Stage 1 is a heavily obfuscated JavaScript stager that pulls a cross-chain lookup list from attacker-controlled TRON addresses (TMfKQEd7TJJa5xNZJZ2Lep838vrzrs7mAP, TXfxHUet9pJVU1BgVkBAbrES4YUc1nGzcG, TLmj13VL4p6NQ7jpxz8d9uYY6FUKCYatSe), with fallback indices on Aptos (0xbe03..0811e, 0x3f0e..5dce3, 0x3414..05837). The index data points at specific Binance Smart Chain transaction hashes (0xf46c..19fc, 0xd33f..58fef, 0xa8cd..16ff) whose input fields carry the XOR-encrypted next-stage payload. Because the loader reads data directly from public RPC endpoints (api.trongrid.io, fullnode.mainnet.aptoslabs.com, bsc-dataseed.binance.org), defenders cannot seize or sinkhole the configuration channel — transactions are immutable and geographically unreachable by traditional takedown.

Stage 2 decrypts a cross-platform Python RAT (Payload1_1_1) and a Python dropper (Payload1_2_1) that fetches the final Omnistealer payload (Payload1_2_1_1). The RAT pivots to one of four hardcoded MongoDB-port (27017) C2 servers — 23.27.20.143, 136.0.9.8, 23.27.202.27, and 166.88.4.2 — using a _V routing byte to decide which operator node receives a given victim. HTTP endpoints /$/boot, /$/z1, /u/f, /u/e, /snv, and /verify-human/{version} handle delivery, file exfiltration, metadata, and environment-variable theft. A Telegram bot (token 7870147428:AAGbYG_eYkiAziCKRmkiQF-GnsGTic_3TTU) is hard-wired as a backup exfiltration channel whenever outbound HTTP to the primary C2 is blocked.

Omnistealer''s credential-collection surface is unusually broad. Targeted password managers include 1Password (aeblfdkhhhdcdjpifhhbdiojplfjncoa), LastPass (hdokiejnpimakedhajhdlcegeplioahd), Dashlane (fdjamakpfbbddfjaooikfcpapjohcfmg), NordPass (eiaeiblijfjekdanodkjadfinkhbfgcd), and Bitwarden (nngceckbapebfimnlniiiahkandclblb). Targeted wallet extensions include MetaMask (nkbihfbeogaeaoehlefnkodbefgpgknn), Phantom (bfnaelmomeimhlpmgjnjophhpkkoljpa), Trust (egjidjbpglichdcondbcbdnbeeppgdph), Coinbase (hnfanknocfeofbddgcijnmhnfnkdnaad), TronLink (ibnejdfjmmkpcnlpebklmnkoeoihofec), Xverse (idnnbdplmphpflfnlkomgpfbpcgelopg), Keplr (dmkamcknogkgcdfhhbddcghachkejeap), and Rabby (acmacodkjbdgmoleebolmdjonilkdbch), plus desktop wallets (Exodus, Atomic, Electrum, Bitcoin Core, Monero, Solana CLI). Chrome, Edge, Brave, Firefox, Opera, Opera GX, Vivaldi, Arc, and Chromium are all scraped for saved logins and cookies. The stealer also enumerates Dropbox, Google Drive, OneDrive, iCloud, Box, Mega, and pCloud client state.

Persistence is established through targeted JavaScript injection into VSCode and Cursor IDE installations — specifically the @vscode/deviceid module — marked with a /*C250617A*/ comment header to prevent re-injection. The Cursor injection is particularly notable because AI-assisted coding IDEs execute user code in a higher-trust context, effectively backdooring the developer''s entire toolchain. Evasion logic blocks execution in AWS EC2, Azure, GCP, Vercel, Amplify, GitHub Actions runners, Docker containers, Kali Linux, and the test hostname EV-CHQG3L42MMQ. A catastrophic-backtracking regex (.search("(((.+)+)+)+$")) is used as an anti-debugger tripwire.

Exfiltrated data is packaged into password-protected ZIP archives named {hostname}${username}_{timestamp}*#{MD5}.zip* with the hardcoded password ,./,./,./ and pushed to /u/f. Ransom-ISAC attributes the campaign with medium confidence to DPRK-aligned actors based on overlaps with the DeceptiveDevelopment, DEV#POPPER, and Operation DreamJob (Lazarus) clusters, consistent with Pyongyang''s documented focus on cryptocurrency theft for sanctions evasion. The Malwarebytes public disclosure on 2026-04-14 made Omnistealer a top-priority monitoring item for every SOC with developer endpoints.

MITRE ATT&CK techniques used in TL-2026-0360

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1132 Data Encoding

Discovery

T1082 System Information Discovery; T1518 Software Discovery

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Credential Access

T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Persistence

T1547 Boot or Logon Autostart Execution

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1586 Compromise Accounts

Affected products and versions in Omnistealer: DPRK-Linked Blockchain-Based Infostealer

  • Google — Chrome
    Vulnerable versions: all
  • Microsoft — Edge
    Vulnerable versions: all
  • Mozilla — Firefox
    Vulnerable versions: all
  • Brave — Brave Browser
    Vulnerable versions: all
  • Opera — Opera / Opera GX
    Vulnerable versions: all
  • Vivaldi — Vivaldi Browser
    Vulnerable versions: all
  • The Browser Company — Arc
    Vulnerable versions: all
  • Microsoft — Visual Studio Code (with @vscode/deviceid)
    Vulnerable versions: all current
  • Anysphere — Cursor IDE
    Vulnerable versions: all current
  • 1Password — 1Password browser extension
    Vulnerable versions: all

Remediation for Omnistealer: DPRK-Linked Blockchain-Based Infostealer

Patches

  • No vendor patch applicable — this is a malware campaign, not a CVE. Ensure VSCode/Cursor are reinstalled from vendor sources after any confirmed injection

Immediate actions

  • Block outbound traffic to C2 IPs 23.27.20.143, 136.0.9.8, 23.27.202.27, 166.88.4.2 on all ports (primary observed: TCP/27017)
  • Hunt for file marker /*C250617A*/ in @vscode/deviceid/dist/index.js inside VSCode and Cursor installations on developer workstations
  • Search GitHub-cloned repos for tailwind.config.js and next.config.mjs files containing the strings global['_V'] and global['r']
  • Quarantine any endpoint observed resolving api.trongrid.io, fullnode.mainnet.aptoslabs.com, or bsc-dataseed.binance.org from non-blockchain workloads
  • Force-rotate credentials for any password manager, browser profile, cloud storage client, or crypto wallet on suspected-infected endpoints
  • Block Telegram Bot API (api.telegram.org) egress from developer and corporate endpoints where not business-justified

Workarounds

  • Developers should run all unknown code inside ephemeral containers or cloud sandboxes rather than on workstations containing credentials
  • Disable automatic execution of postinstall scripts for untrusted npm dependencies (npm config set ignore-scripts true for cloned-repo scoping)
  • Require human review of any config file changes (tailwind/next/postcss) before running local dev servers on code from external recruiters

Longer-term hardening

  • Deploy EDR with JavaScript-in-node_modules tamper detection on developer endpoints
  • Enforce strict network egress policies on developer workstations; whitelist required package registries and block direct public-RPC blockchain access
  • Mandate isolated/ephemeral environments (devcontainers, ephemeral VMs) for running code from third-party GitHub repositories or job-test projects
  • Deploy canary tokens inside password-manager vaults and cloud storage to detect credential theft
  • Implement signed-commit and code-review gates on internal dependency files (tailwind.config.js, next.config.mjs, postcss.config.js)
  • Roll out FIDO2/WebAuthn everywhere to blunt the impact of stolen browser-saved passwords

Weaknesses (CWE) in Omnistealer: DPRK-Linked Blockchain-Based Infostealer

CWE-506, CWE-829, CWE-494

Timeline of Omnistealer: DPRK-Linked Blockchain-Based Infostealer

  • Ransom-ISAC begins tracking Cross-Chain TxDataHiding activity after incident-response engagements uncover trojanized GitHub projects delivered via fake recruiter lures — internally classified as DeceptiveDevelopment follow-on.
  • Google Threat Intelligence publishes UNC5142 EtherHiding report, establishing the broader pattern of blockchain-based malware C2 that Omnistealer later extends to TRON/Aptos/BSC.
  • Omnistealer variant samples surface with JavaScript-in-@vscode/deviceid injection, Cursor IDE targeting, and 60+ wallet extension coverage — a significant expansion over early 2025 DEV#POPPER lineage.
  • Dataconomy publishes the first mainstream report naming Omnistealer and linking it to fake-recruiter GitHub lures targeting South Asian developers.
  • Ransom-ISAC releases 'Cross-Chain TxDataHiding Crypto Heist Part 2' with full IOCs, SHA-256 hashes, C2 list, wallet-extension coverage, and YARA/Sigma detections in the LOCKSTAR/XCTDH_Crypto_Heist repository.
  • Threadlinqs Intelligence opens TL-2026-0360 to track Omnistealer, request simulation coverage, and build detection fleet coverage.
  • Malwarebytes Labs publishes 'Omnistealer uses the blockchain to steal everything it can', reporting ~300,000 compromised credentials across government, defense, financial, food-delivery, and adult-industry victims, triggering broad SOC monitoring.
  • As of 2026-05-29, Omnistealer/XCTDH remains active: its blockchain C2 (TRON/Aptos/BSC) is immutable and explicitly cannot be sinkholed, no takedown or arrests reported, and detection tooling is still being built around it. The parent DPRK fake-recruiter EtherHiding cluster (UNC5342, Contagious Interview, $285M Drift hack) keeps expanding the same technique through 2026.

Sources cited for Omnistealer: DPRK-Linked Blockchain-Based Infostealer

Threats related to Omnistealer: DPRK-Linked Blockchain-Based Infostealer

Detection coverage for TL-2026-0360

As of 2026-04-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0360 across Splunk SPL, Microsoft KQL and Sigma, covering 45 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats