logo

Fake job interviews target developers with new Python backdoor

ID: 7042e241-60fa-55a4-a7ff-57b8506df62e

STIX ID: report--7042e241-60fa-55a4-a7ff-57b8506df62e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Dev Popper is a multi-stage social-engineering campaign targeting software developers with fake job interviews that prompt victims to download an NPM package which ultimately deploys an obfuscated Python RAT; the malware enables persistent remote access, filesystem search and exfiltration (including FTP), remote execution, and keystroke/clipboard logging. Researchers observed the delivery chain (malicious NPM package -> Node.js curl stage -> downloaded Python payload) and note tactics consistent with North Korean groups, although attribution remains inconclusive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.