VDB
GCVE-110-OSM-2026-11603
GCVE-110-OSM-2026-11603
Advisory PublishedCVSS 8.8/10
W3PI-Protocol/w3pi-contracts is a GitHub repository linked to the DPRK-attributed Contagious Interview campaign. The repository is tied to the w3pi.social project that operators used to lure macOS victims into installing trojanized applications delivering the OtterCookie RAT. Published June 2026 and inactive since, the repo forms part of the social-engineering front (fake Web3 project) used to build credibility for the fake interview lure.
Associated C2 infrastructure:
- Primary C2: 162.0.239.85:3000
- OtterCookie operator server: 147.124.202.205 (ports 7671, 7676, 7679)
- Endpoints: /task/mac, /task/tokenlinux
Trojanized applications distributed via associated infrastructure:
The Unarchiver, Presentify, PDFify, Magic Disk Cleaner, Sketch 2026.2, SiteSucker Pro, RAR Extractor Max, Mp3tag, Mole, HextEdit, Folder Preview Pro, Disk Doctor Pro, ServerCat, Bartender.
Malicious file paths:
- .macos (hidden executable in app bundle)
- Info.plist (modified CFBundleExecutable)
- /Library/Application Support/<appname>Extra (PKG preinstall location)
- ~/.task/ (staging directory)
- preinstall, postinstall (PKG scripts)
- tokenlinux.sh (Stage 3 payload)
- parser.js (Final OtterCookie payload)
Contact/lure channel: t.me/W3PIBot (Telegram)
Weaknesses (CWE)
CWE-506Embedded Malicious Code
Risk Scores
CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| unknown | all (affected) | — |
References
Browse GCVE Records
3,521 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.