Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

Contagious Interview

Contagious Interview is a North Korea-linked malware campaign/cluster associated with staged payload delivery, malicious GitHub infrastructure, and software supply-chain abuse across multiple ecosystems. The provided content ties it to DPRK activity and references related malware names BeaverTail and OmniStealer. Reporting cited in the content describes the campaign as operating at scale with hundreds of malicious packages, fake LinkedIn profiles, rotating C2 servers, and malicious interview lures. It has been observed across npm and, in broader reporting, across five ecosystems including npm, PyPI, Go, Rust, and PHP/Packagist. The campaign has also been referenced in GitLab disruption reporting involving malware distribution and fraudulent IT worker operations.

Behaviorally, the content states that Contagious Interview has configured C2 endpoints to inspect IP geolocation, request headers, victim environment details, and runtime conditions before delivering payloads, indicating selective payload staging and victim validation. It has also requested victims disable Docker and other container environments to defeat container isolation and improve infection success. Additional referenced reporting indicates post-compromise tampering with MetaMask wallets. Splunk threat-context mapping in the content associates the campaign with ATT&CK technique T1567 (Exfiltration Over Web Service), indicating web-based exfiltration as relevant observed behavior.

The content further places Contagious Interview in the context of recent software supply-chain compromises, including malicious packages and compromises of legitimate packages, with emphasis on credential theft, CI/CD token theft, and propagation through trusted developer ecosystems. High-confidence indicators from the content are limited to campaign characteristics rather than concrete IOCs: malicious GitHub accounts and infrastructure, rotating C2 servers, fake LinkedIn personas, malicious packages across multiple package registries, C2-side geolocation and environment filtering, and victim instructions to disable Docker/container protections.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

INDICATORS OF COMPROMISE

IOCs tracked for this family

23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
11 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
5 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
7 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 month ago
hash.sha1●●●●●●●●●●●●View more in app2 months ago
uri●●●●●●●●●●●●View more in app2 months ago
uri●●●●●●●●●●●●View more in app2 months ago
uri●●●●●●●●●●●●View more in app2 months ago
hash.sha256●●●●●●●●●●●●View more in app2 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching23

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.