logo

Contagious Interview: Malware delivered through fake developer job interviews

ID: acc25adb-ff21-5675-8008-a987e8d45eb8

STIX ID: report--acc25adb-ff21-5675-8008-a987e8d45eb8

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-03-11

Date Updated: 2026-04-28

Author: Microsoft Defender Experts and Microsoft Defender Security Research Team

...
...

Microsoft Defender Experts exposes the “Contagious Interview” campaign, where attackers pose as recruiters and embed malicious code in fake interview repositories and tasks to trick developers into executing npm packages or repository tasks. The campaign deploys modular backdoors (notably OtterCookie and a beaconing JavaScript agent), follow-on Python and Go backdoors (Invisible Ferret, FlexibleFerret), and commodity stealers to enumerate and exfiltrate secrets (API tokens, wallets, password vaults, keys). The report includes observed behaviors, code-execution and exfiltration patterns, detection/hunting queries, and mitigation recommendations to protect developer workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.