Void Dokkaebi Targets Job Seekers With Malware Hidden In Coding Challenges
ID: 6de73e02-913c-54cb-b0ff-c5c3c191e514
STIX ID: report--6de73e02-913c-54cb-b0ff-c5c3c191e514
Feed Name: Cyber Press
Void Dokkaebi (aka Famous Chollima), a North Korea-linked threat actor, is conducting a worm-like campaign that tricks software developers with fake job interview repositories; compromised projects include hidden .vscode/tasks.json and injected obfuscated JavaScript in config files so that cloning or opening the workspace executes a downloader which installs a DEV#POPPER Node.js RAT. Trend Micro found hundreds of affected repositories and at least two real organizations impacted, indicating active supply-chain-style propagation targeting high-value developer assets like wallet credentials, signing keys, and CI/CD infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
