logo

North Korean Hackers use Code Abuse Tactics for ‘Contagious Interview’ Campaign

ID: 5f37d622-74ea-5049-b9e0-c707d4a0e7eb

STIX ID: report--5f37d622-74ea-5049-b9e0-c707d4a0e7eb

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-01-14

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A DPRK-linked campaign dubbed “Contagious Interview” uses fake recruitment projects to lure developers into downloading malicious repositories that silently execute a two-stage Node.js/Python malware. The threat abuses hidden VS Code tasks, application logic hooks, and malicious npm dependencies to steal credentials, browser wallets, SSH keys and to install a remote access tool and XMRig miner; multiple victims reported financial losses. Researchers attribute the operation to known North Korean operators based on metadata and KST timestamps and observed IOCs (including a command server IP); recommendations include disabling automatic VS Code task execution, enabling workspace trust, rotating credentials and migrating wallets from clean devices, and full OS reinstalls for infected Windows hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.