#OmniStealer

Malware/Tool

2026-03-05 • Learn more about the DEV#POPPER remote access trojan and how to protect your organization from this threat.

OmniStealer is described as a Python-based information stealer deployed in DPRK-linked developer-targeting operations, including Contagious Interview and PolinRider activity. Victims were induced to clone or run trojanized developer projects and packages; staged loaders then used public TRON, Aptos, and BNB Smart Chain RPC infrastructure to retrieve encrypted payload material, decrypt it with embedded XOR keys, and execute it. Reported collection includes browser data, cryptocurrency-wallet and password-manager extension storage, Git credentials, GitHub CLI data, VS Code storage, GitHub Desktop logs, platform credential stores, private keys, seed phrases, and exchange API keys.

Tagged Reports

« Back