logo

Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews

ID: 64cce785-9b59-519b-b31e-34474230cddd

STIX ID: report--64cce785-9b59-519b-b31e-34474230cddd

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

...
...

Void Dokkaebi, a North Korean threat actor, is running a high-severity supply-chain malware campaign called the “Contagious Interview,” which lures software developers with fake job interviews to clone malicious code hosted on platforms like GitHub, GitLab, and Bitbucket; the malware spreads via Visual Studio Code configurations and can propagate through CI/CD pipelines and developer repositories, with Trend Micro reporting over 750 infected repositories and the campaign active since at least 2023.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.