Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligenceremote-access-implantinitial-access-method

North Korean Contagious Interview Campaign Uses Malicious VS Code Projects

Updated 3mo agoFirst seen Jan 20, 20267 sources

North Korea-linked threat actors tied to the long-running Contagious Interview operation have been observed using malicious Microsoft Visual Studio Code (VS Code) projects as part of fake job-assessment lures, instructing targets to clone repositories from GitHub/GitLab/Bitbucket and open them in VS Code. The technique abuses VS Code tasks.json configuration—specifically "runOn": "folderOpen"—to trigger execution when a folder is opened, pulling staged payloads from attacker-controlled infrastructure (including Vercel-hosted domains) and ultimately deploying backdoors such as BeaverTail and InvisibleFerret that enable remote code execution and follow-on control. Recent iterations reportedly add multi-stage droppers embedded in task configuration content and disguised as benign files (e.g., spell-check dictionaries) to improve resilience if network retrieval fails, and include command-and-control behavior that can execute attacker-supplied JavaScript from a remote server (e.g., ip-regions-check.vercel[.]app).

Separate reporting on North Korean APT trends indicates continued reliance on fraudulent IT employment schemes and recruitment-platform abuse to gain access to Western organizations, including long-term social engineering and persistent remote access via legitimate tools (e.g., AnyDesk, Google Remote Desktop) and VPN/location obfuscation. This broader pattern aligns with the same overarching tradecraft used in developer-targeted “interview” lures: leveraging hiring workflows and developer tooling to establish initial access and persistence while reducing suspicion, particularly in environments with remote-work infrastructure and developer workstations.

Share:
North Korean Contagious Interview Campaign Uses Malicious VS Code Projects
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jan 21, 20265mo ago

Recorded Future exposed PurpleBravo victim and infrastructure scope

Recorded Future's Insikt Group published findings tying the PurpleBravo cluster to 3,136 likely target IPs, 20 potential victim organizations, LinkedIn recruiter personas, and separate C2 infrastructure for BeaverTail and GolangGhost. The report also noted operational overlaps with the North Korean IT-worker fraud campaign known as Wagemole/PurpleDelta.

Jan 20, 20265mo ago

Jamf disclosed new VS Code and npm infection methods

In January 2026, Jamf Threat Labs reported that the Contagious Interview campaign had evolved to abuse VS Code repository trust and task configuration files to trigger malicious commands, including a previously unseen JavaScript backdoor on macOS. Jamf also identified a new Node.js ecosystem infection method in which malicious code executes during a standard npm install.

Jan 18, 20265mo ago

ASEC summarized December 2025 DPRK APT trends

AhnLab ASEC published a trend report consolidating North Korea-aligned activity observed in December 2025, including Famous Chollima fake IT worker operations and Lazarus malware delivery via a WinRAR exploit. The report highlighted a broader shift toward combining social engineering, remote-work abuse, and software exploitation.

Dec 1, 20257mo ago

Jamf first observed VS Code task abuse in Contagious Interview

Jamf Threat Labs first noted in December 2025 that DPRK-linked attackers were abusing Visual Studio Code tasks.json files with the runOn: folderOpen setting to execute code when a victim opened a cloned repository. The technique delivered malware including BeaverTail and InvisibleFerret through job-assessment lures.

Lazarus used Pharos.rar to exploit WinRAR flaw CVE-2025-8088

Lazarus Group distributed a malicious archive named Pharos.rar that exploited WinRAR path traversal vulnerability CVE-2025-8088 to place a BAT file in the Startup folder. The infection chain deployed a multi-stage Python loader leading to the Blank Grabber infostealer, using Dropbox, Pastebin, and Telegram in the process.

Jan 1, 20251y ago

Jasper Sleet linked to PiKVM-based fake IT worker operation

Microsoft Incident Response (DART) linked a Famous Chollima case using PiKVM hardware-based remote control to the Jasper Sleet threat cluster. The technique was used to bypass endpoint detection and response controls while maintaining remote access.

Famous Chollima expanded fake IT worker intrusions via hiring platforms

During 2025, North Korea-aligned Famous Chollima used fake IT worker schemes, identity theft, GitHub pull-request outreach, VPNs, and remote desktop tools such as AnyDesk and Google Remote Desktop to obtain and maintain covert access to corporate environments. The activity also involved soliciting victims' personal identity information.

Aug 1, 20242y ago

PurpleBravo infrastructure targeted thousands of IPs worldwide

Recorded Future assessed the North Korea-linked PurpleBravo/Contagious Interview cluster targeted 3,136 IP addresses and 20 potential victim organizations across multiple sectors and regions. The activity primarily affected targets in South Asia and North America between August 2024 and September 2025.

Dec 1, 20233y ago

Contagious Interview campaign active against developers and IT professionals

North Korea-linked operators behind the Contagious Interview campaign were active by late 2023, using fake job and interview lures to target developers and IT workers, especially in blockchain and cryptocurrency. The campaign supported espionage, credential theft, initial access, and financially motivated activity.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

68 LINKEDOpen in app
Affected products
23 linked
GithubVisual Studio CodeLinkedinGithubGitlabGitlabAnydeskMacosWindows DefenderNodejsTelegramMetamaskVercelPowershellBitbucketActive DirectoryPythonDropboxDropboxWinrarWinrarMetamaskMacos
Organizations
31 linked
Microsoft CorporationGitHubJamfLinkedinAstrillRecorded FutureMastercardThe Hacker NewsGitLabVercelAnyDesk Software GmbHAtlassianElectrum Technologies GmbHDiscordJfrogBitbucketNotionDropboxWinRARAny.RunTelegramMetamaskPastebinOpenSourceMalwareGoogleFinal Round AISimplifyAIApplyRed AsgardExodus MovementSecurity Alliance
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.