{"id":1067,"date":"2026-07-17T09:11:27","date_gmt":"2026-07-17T07:11:27","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=1067"},"modified":"2026-07-20T09:11:55","modified_gmt":"2026-07-20T07:11:55","slug":"fake-coding-tests-deliver-ottercookie-aligned-malware-hidden-in-svg-flag-images","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/17\/fake-coding-tests-deliver-ottercookie-aligned-malware-hidden-in-svg-flag-images\/","title":{"rendered":"Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">North Korean threat actors linked to the&nbsp;<a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-npm-packages-mimic.html\" target=\"_blank\" rel=\"noreferrer noopener\">Contagious Interview<\/a>&nbsp;campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser credential and crypto wallet stealer, a file stealer, a Socket.IO-based remote access trojan (RAT), and a clipboard stealer,&#8221; Elastic Security Labs&nbsp;<a href=\"https:\/\/www.elastic.co\/security-labs\/contagious-interview-malware-svg-steganography\" target=\"_blank\" rel=\"noreferrer noopener\">said<\/a>&nbsp;in a report shared with The Hacker News.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/17\/fake-coding-tests-deliver-ottercookie-aligned-malware-hidden-in-svg-flag-images\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2026\/07\/north-korea-linked-hackers-hide.html?m=1\">Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images<\/a><span class=\"screen-reader-text\">: Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>North Korean threat actors linked to the&nbsp;Contagious Interview&nbsp;campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. &#8220;Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[72,39],"class_list":["post-1067","post","type-post","status-publish","format-standard","hentry","category-vulnerability","tag-72","tag-north-korea"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1067","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=1067"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1067\/revisions"}],"predecessor-version":[{"id":1068,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1067\/revisions\/1068"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=1067"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=1067"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=1067"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}