highPhishing

Contagious Interview Campaign (North Korea-linked)

First seen Sep 22, 2026 · Updated Sep 22, 2026

north-koreadprkcryptocurrencysocial-engineeringfake-job-lurecredential-theftsupply-chainagent-relevant

North Korean state-sponsored actors have conducted a large-scale social engineering campaign dubbed 'Contagious Interview,' luring web developers, engineers, and crypto specialists with fake job interviews to deploy malware. The operation has compromised over 30,000 devices across 100+ countries and stolen $10.71M in cryptocurrency and credentials from over 7,000 wallets.

Technical Analysis

The campaign relies on fake recruiter outreach and trojanized coding assessments or npm/GitHub project files delivered as 'technical interview' tasks, which install information-stealing malware (historically associated with BeaverTail and InvisibleFerret loaders) to harvest browser-stored credentials, crypto wallet keys, and session tokens. Victims are typically developers who clone and execute malicious repositories or npm packages under the guise of completing a coding challenge, giving attackers code-execution on developer workstations. Because many of the targeted developers work on tooling, browser extensions, and backend services that increasingly integrate with AI coding assistants and agent frameworks, compromised developer machines can leak API keys, cloud credentials, and secrets used by CI/CD pipelines and AI agents, enabling downstream supply-chain compromise of agent-integrated software. Organizations that allow engineers to install unvetted packages or run agent-assisted coding workflows on the same hosts used for job-search related downloads face elevated risk of credential and secret exfiltration feeding into agent tool-use contexts.

Affected Systems

Developer workstations (Windows, macOS, Linux) running Node.js/npm environments; browsers with saved credentials or crypto wallet extensions (MetaMask, etc.); systems used for freelance/remote job applications in tech and crypto sectors

Indicators of Compromise

  • Fake recruiter personas on LinkedIn/Upwork/freelance platforms
  • Malicious npm packages disguised as coding-test repositories
  • BeaverTail JavaScript stealer payloads
  • InvisibleFerret Python backdoor
  • C2 domains associated with DPRK Lazarus-linked infrastructure (rotating, consult advisory for current IOC list)

Remediation Steps

  1. 1

    Isolate developer environments

    Require sandboxed/VM-based execution for any third-party coding-test or interview-related code before running on production or credential-bearing machines.

  2. 2

    Rotate exposed credentials

    Immediately rotate API keys, cloud credentials, and crypto wallet keys for any employee who participated in recent remote 'interview' processes involving code execution.

  3. 3

    Deploy endpoint monitoring

    Use EDR to detect known BeaverTail/InvisibleFerret indicators and unusual outbound connections from developer workstations.

  4. 4

    Vet third-party packages

    Enforce package allow-listing and code review for npm/GitHub dependencies pulled from unsolicited job-related sources.

  5. 5

    Security awareness training

    Educate engineering and crypto staff on North Korean fake-recruiter tactics and the risks of running unverified 'technical assessment' code.

Industries Most Exposed

technologycryptocurrencysoftware developmentfreelance/gig economyfinance

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.