logo

DPRK's 'Contagious Interview' Spawns Malicious Npm Package Factory

ID: 14d51528-9d1f-5a7b-8a41-36b85d85da25

STIX ID: report--14d51528-9d1f-5a7b-8a41-36b85d85da25

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-12-02

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

North Korean threat actors operate the persistent 'Contagious Interview' campaign that lures developers with fake job interviews and delivers hundreds of malicious npm packages (over 197 packages and ~31,000+ downloads) to install OtterCookie/BeaverTail malware. The malware provides RAT, keystroke logging, screenshot capture, clipboard theft, and credential/cryptocurrency exfiltration; attackers leverage GitHub and Vercel infrastructure for staged delivery and maintain continuous, product-like operations against Web3 and blockchain developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.