North Korean Hackers use Code Abuse Tactics for ‘Contagious Interview’ Campaign
ID: 5f37d622-74ea-5049-b9e0-c707d4a0e7eb
STIX ID: report--5f37d622-74ea-5049-b9e0-c707d4a0e7eb
Feed Name: cybersecurityNews.com
A DPRK-linked campaign dubbed “Contagious Interview” uses fake recruitment projects to lure developers into downloading malicious repositories that silently execute a two-stage Node.js/Python malware. The threat abuses hidden VS Code tasks, application logic hooks, and malicious npm dependencies to steal credentials, browser wallets, SSH keys and to install a remote access tool and XMRig miner; multiple victims reported financial losses. Researchers attribute the operation to known North Korean operators based on metadata and KST timestamps and observed IOCs (including a command server IP); recommendations include disabling automatic VS Code task execution, enabling workspace trust, rotating credentials and migrating wallets from clean devices, and full OS reinstalls for infected Windows hosts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
