logo

The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry

ID: 0bd9a8c5-b5f8-5ad3-82e6-ec53baa5d3b4

STIX ID: report--0bd9a8c5-b5f8-5ad3-82e6-ec53baa5d3b4

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

Socket researchers uncovered an expanded "Contagious Interview" campaign linked to North Korea that has published over 1,700 malicious packages across npm, PyPI, Go, Rust, and Packagist; the packages impersonate legitimate developer tooling and act as loaders that rewrite Google Drive links, fetch ZIP archives, and deliver platform-specific second-stage payloads while using a cloned-project GitHub persona (maxcointech1010) to provide social proof.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.