logo

North Korean Hackers Exploit Code Repositories in “Contagious Interview” Campaign

ID: f4a1144d-4a9e-53bd-b567-4dbea3fa8571

STIX ID: report--f4a1144d-4a9e-53bd-b567-4dbea3fa8571

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

SEAL details the "Contagious Interview" campaign attributed to DPRK actors that weaponises code-repository lures and VS Code task hooks to deploy a dual Node.js/Python infostealer and RAT, exfiltrating credentials and cryptocurrency wallets (and deploying an XMRig miner); multiple victims with financial losses and concrete IOCs/TTPs are documented, and recommended mitigations include disabling automatic VS Code tasks, enforcing workspace trust, and scanning for hidden artefacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.