Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
identity-impersonation-fraudphishing-campaign-intelligencestate-sponsored-espionagecredential-stealer-activity

North Korean Contagious Interview Campaign Targets Developers With Fake Recruiting Lures

Updated 3mo agoFirst seen Feb 2, 20264 sources

Reporting describes North Korea–linked “Contagious Interview” activity in which attackers pose as recruiters and use fake job processes to compromise software developers. The operation uses deceptive LinkedIn personas and malicious “coding test” repositories to deliver malware (including BeaverTail and follow-on multi-platform backdoors/RATs), creating downstream supply-chain risk when victims run the code on corporate devices with privileged access. Separately, a real-world example of the same broader tactic was highlighted when an AI security firm’s CEO reported a deepfake job applicant and other red flags during a hiring process, reinforcing that adversaries are operationalizing identity fraud and synthetic media to increase the success rate of developer-focused intrusion attempts.

The developer ecosystem continues to be a high-value target for initial access and credential theft, as shown by a separate incident in which a malicious Open VSX extension masquerading as an Angular language tool reached thousands of downloads and was reported to steal GitHub/NPM credentials, browser tokens, and crypto-wallet data while using resilient C2 techniques. In parallel, a high-severity CI/CD weakness was disclosed in the Eclipse Theia website repository (CVE-2026-1699), where a pull_request_target GitHub Actions workflow could allow untrusted PR code execution with access to repository secrets and broad GITHUB_TOKEN permissions—conditions that could enable package publishing, website tampering, or code pushes if exploited. Together, the activity underscores elevated risk around developer hiring workflows, developer tooling marketplaces, and CI pipelines as converging attack surfaces for credential theft and supply-chain compromise.

Share:
North Korean Contagious Interview Campaign Targets Developers With Fake Recruiting Lures
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Feb 1, 20265mo ago

PurpleBravo campaign escalation against developers is reported

Reporting described North Korean threat group PurpleBravo as escalating the Contagious Interview campaign by targeting developers with fake LinkedIn recruiters and malicious GitHub repositories. The activity was said to have affected 3,136 IP addresses and more than 20 organizations, increasing software supply-chain risk.

Expel identifies suspected deepfake North Korean job applicant

Expel CEO Jason Rebholz described a suspected North Korea-linked fake IT worker who applied for a security researcher role and appeared in a video interview that showed signs of deepfake manipulation. Analysis by Moveris reportedly confirmed the interview video was a deepfake.

Jan 30, 20265mo ago

CVE-2026-1699 disclosed in Eclipse Theia GitHub Actions workflow

A code execution vulnerability in the Eclipse Theia Website repository's GitHub Actions workflow was identified and disclosed as CVE-2026-1699. The issue stemmed from use of `pull_request_target` while executing untrusted pull request code, potentially exposing secrets and enabling malicious changes to Theia assets.

Open VSX malware campaign compromises over 5,000 developer systems

The weaponized Open VSX extension remained undetected for about two weeks and reached 5,066 downloads, leading to the compromise of more than 5,000 developer workstations. The malware used Solana blockchain transaction memos for command-and-control and a Google Calendar fallback mechanism.

Jan 16, 20265mo ago

Malicious Open VSX extension is published

A malicious extension masquerading as "Angular Language Service" was published to the Open VSX marketplace. It bundled legitimate Angular and TypeScript components with encrypted malware aimed at stealing developer credentials, tokens, and cryptocurrency wallets.

Apr 1, 20242y ago

Amazon begins blocking suspected DPRK fake IT worker applicants

Amazon said it had blocked more than 1,800 suspected North Korean employment-fraud applicants from joining its workforce since April 2024. The company also reported a quarter-over-quarter increase in DPRK-affiliated applications.

Jan 1, 20233y ago

Contagious Interview campaign first observed targeting developers

A North Korea-linked campaign dubbed "Contagious Interview" was first noted in 2023, using fake recruiter personas and malicious coding tests to target software developers. The activity later became associated with malware families including BeaverTail and GolangGhost.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Threat actors
3 linked
Affected products
4 linked
NpmGithubVisual Studio CodeGithub
Organizations
13 linked
LinkedinGitHubGoogleQualysVirustotalCrowdStrikeAstrill VPNThe RegisterAmazon Web ServicesAnthropicExpelVercelMoveris
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

North Korean Contagious Interview Campaign Targets Developers With Fake Recruiting Lures | Mallory