logo

Fake recruiter coding tests target devs with malicious Python packages

ID: e07a27e3-aa71-5f20-b600-73541941af86

STIX ID: report--e07a27e3-aa71-5f20-b600-73541941af86

Feed Name: ReversingLabs Blog

Threat Score
85/100

Date Published: 2024-09-10

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

ReversingLabs details an active campaign (VMConnect) that distributes malicious Python packages and GitHub repos posing as developer coding tests and fake job interviews to trick developers into executing code; the malware (in __init__.py and .pyc files) contains Base64-encoded downloader functionality that contacts a C2 to execute commands and fetch further payloads. The report links the activity to North Korea’s Lazarus Group, describes evidence including a compromised developer and removed GitHub repositories, and warns that this supply-chain-style technique enables initial access and potential lateral movement to steal data or deploy backdoors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.