DPRK's 'Contagious Interview' Spawns Malicious Npm Package Factory
ID: 14d51528-9d1f-5a7b-8a41-36b85d85da25
STIX ID: report--14d51528-9d1f-5a7b-8a41-36b85d85da25
Feed Name: Dark Reading
Date Published: 2025-12-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
North Korean threat actors operate the persistent 'Contagious Interview' campaign that lures developers with fake job interviews and delivers hundreds of malicious npm packages (over 197 packages and ~31,000+ downloads) to install OtterCookie/BeaverTail malware. The malware provides RAT, keystroke logging, screenshot capture, clipboard theft, and credential/cryptocurrency exfiltration; attackers leverage GitHub and Vercel infrastructure for staged delivery and maintain continuous, product-like operations against Web3 and blockchain developers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
