Skip to main content
Mallory
Back to intelligence
state-sponsored-espionagecryptocurrency-platform-riskphishing-campaign-intelligencecredential-stealer-activity

DPRK-Linked Contagious Interview Campaign Stole Crypto via Fake Developer Job Tests

Updated 3d agoFirst seen Apr 17, 202626 sources

North Korea-linked operators tracked as HexagonalRodent, Contagious Interview, and overlaps of Lazarus/Famous Chollima used fake recruiter outreach on LinkedIn and sham company infrastructure to lure software and Web3 developers into opening malicious coding assessments. Researchers said the campaign delivered malware including BeaverTail, InvisibleFerret, and OtterCookie through backdoored GitHub repositories, rogue npm content, malicious VS Code tasks.json execution, and weaponized Git hooks such as pre-commit and post-checkout. The malware targeted Windows, macOS, and Linux systems, stealing browser credentials, keychains, wallet data, seed phrases, and developer secrets while maintaining persistence and remote access.

Share:
DPRK-Linked Contagious Interview Campaign Stole Crypto via Fake Developer Job Tests
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

14 events from the most recent confirmed update back to the earliest known activity.

14 EVENTS
Jun 16, 20264d ago

Developer spots malicious npm hook in fake recruiter coding test

On 2026-06-16, Python developer Roman Imankulov reported a suspected social-engineering supply-chain attack in which a fake recruiter sent him a malicious Node.js repository during a hiring process. He identified a backdoor in app/test/index.js and an npm prepare post-install hook that would execute attacker-controlled payloads during npm install, avoiding compromise by analyzing the code in an isolated environment.

Python dev saved from disaster by intuition...and AI
Jun 11, 20269d ago

Kmsec reports DPRK job-advert lures hosted on Google Docs

On 2026-06-11, a Kmsec article highlighted North Korea-linked job advertisement activity using Google Docs, associated in the reference with the Famous Chollima cluster. The reporting points to a new lure or delivery mechanism within the broader recruiter-themed campaign targeting developers.

Post by @lazarusholic.bsky.social - Bluesky
May 28, 202623d ago

TrendAI reports Cython-compiled InvisibleFerret variants

On 2026-05-28, TrendAI Research reported that the DPRK-aligned Void Dokkaebi/Famous Chollima cluster had evolved InvisibleFerret from readable Python into Cython-compiled native binaries delivered as .pyd and .so files. The report said the campaign still used fake job interview lures and BeaverTail staging while adding techniques to hinder detection and analysis.

Void Dokkaebi Cython Malware Targets Global Developers
May 27, 202624d ago

Developer says they were likely targeted in DPRK malware campaign

On 2026-05-27, a developer posted that they were likely targeted by North Korea in a sophisticated malware campaign aimed at developers, explicitly referencing Contagious Interview and VS Code themes.

Post by @lazarusholic.bsky.social - Bluesky
May 16, 20261mo ago

Red Asgard analyzes OtterCookie as a live-surveillance implant

On 2026-05-16, Red Asgard published technical analysis separating OtterCookie from BeaverTail and InvisibleFerret, describing it as a JavaScript/Node.js RAT using Socket.IO for persistent command-and-control and continuous collection from active developer workstations. The analysis also linked delivery to malicious npm packages and Vercel-hosted staging infrastructure.

Hunting Lazarus Part VIII: OtterCookie ? Red Asgard Blog
May 12, 20261mo ago

Researchers report malicious Git hooks in coding-test repositories

On 2026-05-12, researchers reported that Lazarus-linked actors were using malicious Git hooks in fake coding-test repositories so that commits or branch switches would trigger platform-specific malware delivery. The activity was tied to the Contagious Interview campaign and associated with BeaverTail and InvisibleFerret.

North Korean Hackers Weaponize Git Hooks to Deploy Cross-Platform Malware
May 8, 20261mo ago

NitroGem analysis reveals npm-install trojan using Google Docs C2

On 2026-05-08, a GitHub Gist analysis documented NitroGem, a malicious GitHub repository disguised as a React/Web3 dApp used in fake job-interview workflows to target developers. The trojan executed during npm install via a prepare script, fetched a public Google Doc to derive its C2 URL, exfiltrated the victim's process.env, and ran attacker-supplied JavaScript for remote code execution.

NitroGem - Developer-Targeted Trojan Disguised as a Web3 dApp · GitHub
Apr 23, 20262mo ago

Developer reports sophisticated fake-job malware incident

On 2026-04-23, reporting detailed how Serbia-based developer Boris Vujičić was lured through LinkedIn and realistic interviews into running a malicious coding test on macOS, after which attackers exfiltrated Chrome passwords, Keychain data, and MetaMask wallet information within 56 seconds. Incident responders at zeroShadow assessed that North Korean government-linked actors were likely responsible.

Dev targeted by sophisticated job scam • The Register
Apr 22, 20262mo ago

HexagonalRodent compromises fast-draft VSX extension

In early 2026, the HexagonalRodent subgroup expanded beyond fake coding tests into at least one supply-chain compromise by tampering with the fast-draft VSX extension to distribute OtterCookie.

Inside Lazarus: How North Korea uses AI to industrialize attacks on developers | Expel

HexagonalRodent steals crypto from developer victims in Q1 2026

During the first three months of 2026, Expel assessed that the DPRK-linked HexagonalRodent operation exfiltrated 26,584 cryptocurrency wallets from 2,726 infected developer systems, with exposed wallets tied to up to $12 million in crypto assets. The campaign targeted Web3 developers with fake job offers and backdoored coding assessments using BeaverTail, OtterCookie, and InvisibleFerret.

Inside Lazarus: How North Korea uses AI to industrialize attacks on developers | Expel

Expel publishes AI-assisted HexagonalRodent investigation

On 2026-04-22, Expel published findings on HexagonalRodent, describing a DPRK-linked operation targeting Web3 developers with fake job offers, BeaverTail, OtterCookie, and InvisibleFerret, and extensive use of generative AI for malware development, phishing infrastructure, and evasion testing. Expel also said it uncovered internal panels and workflows indicating a multi-team operation.

Inside Lazarus: How North Korea uses AI to industrialize attacks on developers | Expel
Jan 27, 20265mo ago

Fake Font variant abuses VS Code projects to infect developers

On 2026-01-27, researchers described a North Korea-linked 'Fake Font' campaign in which fake recruiters sent developers to GitHub projects containing malicious VS Code tasks and JavaScript disguised as font files, leading to InvisibleFerret infections across Windows, macOS, and Linux.

North Korea hides malware in open-source projects | Cybernews
Jan 16, 20251y ago

Researchers document OtterCookie malware in Contagious Interview

By early 2025, reporting identified OtterCookie as a new malware family used in the Contagious Interview operation alongside BeaverTail and InvisibleFerret, expanding the campaign's tooling against developer targets.

OtterCookie, new malware used in Contagious Interview campaign | セキュリティナレッジ | NTTセキュリティ・ジャパン株式会社
Nov 22, 20233y ago

Unit 42 links Contagious Interview to DPRK recruiter-themed malware campaign

On 2023-11-22, Palo Alto Networks Unit 42 reported that North Korean threat actors were running the Contagious Interview campaign, impersonating recruiters to infect software developers with BeaverTail and InvisibleFerret malware via fake job interview lures and rogue GitHub/npm content.

North Korean Hackers Pose as Job Recruiters and Seekers in Malware Campaigns
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

91 LINKEDOpen in app
Affected products
25 linked
AnydeskMetamaskBrave BrowserLinkedinVisual Studio CodeGithubChatgptCursorNodejsWindowsVercelDiscord1passwordZoomMacos1passwordExpressFilezilla ServerNpmGoogle SearchExpressGitMacosCursorClaude
Organizations
47 linked
GoogleAnyDesk Software GmbHTrendAI ResearchLinkedinExpelGitHubMicrosoft CorporationOpenaiMeta PlatformsCrowdStrikeCursorVercelOpenSourceMalwareAnimaAnysphereAgilebitsThe RegisterSocketPalo Alto NetworksCybernewsFalconFeedsAnthropicZoom CommunicationsRecorded FuturePhylum1passwordCoinbasePhantom TechnologiesBlueskyReutersLockheed Martinnpm, Inc.BoeingJumpCloudNTT Securitynexos.aiHetznerHostGatorThe Hacker NewsObfuscator.ioStep FinanceZeroShadowDrift ProtocolKelpDAOGenusix LabsAbuseRadarDenv
Breaches
2 linked
STEPFINANCE-2026-04JUMPCLOUD-2023-11
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.