OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign Leaks Its Own Operator Credentials — Threadlinqs Intelligence
As of 2026-07-17, OtterCandy (js.ottercandy) Node.js RAT/Stealer — WaterPlum's Polymarket-Themed ClickFake Interview Campaign Leaks Its Own Operator Credentials is a high-severity malware threat attributed to WageMole (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-1441 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: WageMole · North Korea (DPRK) · FINANCIAL
OtterCandy (js.ottercandy) is a cross-platform Node.js RAT and cryptocurrency/credential stealer deployed by the North Korea-linked WaterPlum (Famous Chollima/PurpleBravo) actor as part of the ongoing
OtterCandy is a Node.js-based remote access trojan and information stealer first uploaded to VirusTotal in February 2025 (initially misclassified as OtterCookie) and distributed in the wild from July 2025 onward across Windows, macOS, and Linux — a platform-unification step up from WaterPlum's earlier per-OS toolset (GolangGhost for Windows, FrostyFerret for macOS). The malware is functionally a fusion of two earlier WaterPlum families, RATatouille and OtterCookie, and communicates with its C2 over the Socket.IO real-time protocol, giving operators arbitrary remote command execution. Version 1 exfiltrated a username plus partial Chromium browser-extension data from four wallet extensions; version 2 (deployed August 2025) added a unique client_id per-victim tracking field, expanded targeting to seven browser wallet extensions, moved to full Chromium user-data-directory exfiltration, and introduced an anti-forensic 'ss_del' command that deletes the persistence registry keys and files belonging to OtterCandy's companion persistence implant, DiggingBeaver, to frustrate incident response. OtterCandy also self-resurrects by re-registering a Node.js SIGINT handler so that attempts to Ctrl-C or kill the process relaunch it.
OtterCandy is delivered through WaterPlum's ClickFake Interview operation, a sub-cluster of the broader, DPRK-attributed Contagious Interview campaign (active since at least December 2022, tracked jointly as CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, PurpleBravo, Tenacious Pungsan, UNC5342, Void Dokkaebi, and WaterPlum; MITRE ATT&CK Group G1052). Operators pose as recruiters (including via three known front companies — BlockNovas LLC, Angeloper Agency, and SoftGlide LLC) on LinkedIn, Telegram, and email, luring blockchain/crypto developers and job seekers into fake 'technical interview' or coding-assessment flows. Victims are pushed through ClickFix-style pages that instruct them to copy/paste and execute attacker-supplied shell commands, or to install a trojanized 'interview' application, ultimately dropping BeaverTail (JavaScript npm-hosted stealer), InvisibleFerret (Python backdoor), and/or OtterCandy, frequently staged via malicious npm loaders XORIndex and HexEval.
The specific hunt trigger for this record is a parallel, thematically identical operation surfaced by OX Security on 2026-07-12: a malicious npm package family (polymarket-kit and related polymarket-*/clob-*/kelly-* named packages) impersonating the Polymarket prediction-market platform's trading tooling to target high-value cryptocurrency users. After obfuscated multi-stage dropper execution, the payload establishes a WebSocket connection to C2 domain svganchordev[.]net (masquerading as an image-hosting site), giving operators an 'exec' primitive for arbitrary remote command execution — functionally a RAT consistent with WaterPlum/OtterCandy-style tradecraft. The malware enumerates and decrypts local browser-extension wallet stores (MetaMask, Phantom, TronLink, Coinbase Wallet, OKX Wallet, Trust Wallet, Rabby Wallet) and desktop wallets (Exodus, Guarda, Electrum, Atomic Wallet), and separately harvests Google Cloud, AWS, and Azure credentials/configuration files, uploading everything to the C2 over the same WebSocket channel. Researchers discovered the operators had left their own operational-security failure baked into the published package: a cleartext OpenSSH ed25519 private key (public key ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIKtHcyfcCaE2XEiBHlMEjP6VjIz3Ck8gaEDE7Q+gwN4w) tied to account testm@DESKTOP-PO28IS1, plus additional GitLab private SSH keys, all shipped in cleartext inside the npm package contents — exposing attacker-controlled infrastructure to defenders and researchers.
The broader Polymarket-impersonation npm threat landscape in 2026 includes multiple parallel, possibly overlapping operations: a hijacked verified GitHub organization (dev-protocol) used to distribute typosquatted Polymarket trading-
Weaknesses (CWE)
CWE-798, CWE-522, CWE-506
Target sectors: cryptocurrency, finance, technology, software development, blockchain defi
Target regions: Global, germany, united kingdom, france, netherlands, sweden, switzerland, japan, North America
References
- Malware-Slop: Crypto Stealer Impersonating Polymarket Exposes Its Own Credentials
- OtterCandy, malware used by WaterPlum (Malpedia)
- ClickFake Interview Campaign Used by Threat Actors to Deliver OtterCandy Malware
- North Korean Hackers Combine BeaverTail and OtterCookie into Advanced JS Malware
- North Korea's WaterPlum APT Deploys Node.js OtterCandy RAT for Crypto Theft with Anti-Forensic Module
- OtterCandy, malware used by WaterPlum - Live Threat Intelligence (OffSeq Threat Radar)
- Contagious Interview, DeceptiveDevelopment, Gwisin Gang, Tenacious Pungsan, DEV#POPPER, PurpleBravo, TAG-121, Group G1052 (MITRE ATT&CK)
- Contagious Interview: Malware delivered through fake developer job interviews
- Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys
- The Polymarket Trap: A Fake Arbitrage Bot, Ten npm Accounts, and Four Ways to Deliver an Infostealer
- A Patient Trojan Dropper: polymarket-stake-math Steals Wallet Keys, Browser Sessions, and Telegram from Crypto Developers
- Contagious Interview gets an upgrade for 2026 - A comprehensive analysis
- New wave of 'fake interviews' use 35 npm packages to spread malware
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589, T1593, T1583.001, T1583.006, T1585.001, T1587.001, T1588.001, T1608.001, T1566.003, T1195.002