logo

Contagious Interview: VS Code to RAT

ID: 1512f5d2-4cc8-53aa-9cf0-2875c1b3f132

STIX ID: report--1512f5d2-4cc8-53aa-9cf0-2875c1b3f132

Feed Name: Ransomware ISAC Blog

Threat Score
90/100

Date Published: 2026-03-16

Date Updated: 2026-08-21

Author: [email protected] (François-Julien Alcaraz & Yashraj Solanki)

...
...

This report documents the "Contagious Interview" campaign attributed to DPRK-affiliated actors that uses fake LinkedIn recruitment and Google Meet interviews to pressure developers to open a malicious GitHub repository; opening the repo in VS Code triggers an autorun task which starts a Next.js process that eval()s a staged JavaScript payload, resulting in a Node.js RAT that beacons to operator-controlled C2 servers, performs system fingerprinting, and enables remote code execution. The analysis includes code excerpts, infrastructure mapping (IPs, domains, endpoints), YARA detection, and actionable mitigations (disable automatic tasks, inspect .vscode and config files, monitor dev environment network traffic).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.