Contagious Interview: Malware delivered through fake developer job interviews
ID: acc25adb-ff21-5675-8008-a987e8d45eb8
STIX ID: report--acc25adb-ff21-5675-8008-a987e8d45eb8
Feed Name: Microsoft Security
Date Published: 2026-03-11
Date Updated: 2026-04-28
Author: Microsoft Defender Experts and Microsoft Defender Security Research Team
Microsoft Defender Experts exposes the “Contagious Interview” campaign, where attackers pose as recruiters and embed malicious code in fake interview repositories and tasks to trick developers into executing npm packages or repository tasks. The campaign deploys modular backdoors (notably OtterCookie and a beaconing JavaScript agent), follow-on Python and Go backdoors (Invisible Ferret, FlexibleFerret), and commodity stealers to enumerate and exfiltrate secrets (API tokens, wallets, password vaults, keys). The report includes observed behaviors, code-execution and exfiltration patterns, detection/hunting queries, and mitigation recommendations to protect developer workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
