logo

Void Dokkaebi Targets Job Seekers With Malware Hidden In Coding Challenges

ID: 6de73e02-913c-54cb-b0ff-c5c3c191e514

STIX ID: report--6de73e02-913c-54cb-b0ff-c5c3c191e514

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Varshini

...
...

Void Dokkaebi (aka Famous Chollima), a North Korea-linked threat actor, is conducting a worm-like campaign that tricks software developers with fake job interview repositories; compromised projects include hidden .vscode/tasks.json and injected obfuscated JavaScript in config files so that cloning or opening the workspace executes a downloader which installs a DEV#POPPER Node.js RAT. Trend Micro found hundreds of affected repositories and at least two real organizations impacted, indicating active supply-chain-style propagation targeting high-value developer assets like wallet credentials, signing keys, and CI/CD infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.