BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

North Korean npm Malware Targets Developers in Fake Job Interviews

North Korean Hackers Launch New npm Malware Campaign Targeting Developers Through Fake Job Offers

  • Researchers uncovered 35 new malicious npm packages tied to North Korean threat actors.
  • The packages were downloaded over 4,000 times and posted from 24 npm accounts.
  • The campaign uses encoded Malware loaders to deliver information stealers and remote access tools.
  • Attackers pose as recruiters and target developers with fake job assignments on sites like LinkedIn.
  • The operation aims to steal cryptocurrency and sensitive data from compromised developer systems.

Cybersecurity specialists have identified 35 new harmful npm packages connected to the ongoing “Contagious Interview” cyber attack campaign, which is attributed to state-sponsored groups from North Korea. The new wave of malicious software appeared on the npm open-source package platform and targets developers and job seekers.

- Advertisement -

According to Socket, these packages have been uploaded from 24 separate npm accounts and have received over 4,000 downloads. Six of these packages, including “react-plaid-sdk,” “sumsub-node-websdk,” and “router-parse,” remained publicly available at the time of discovery.

Each package contains a tool called HexEval, which is a hex-encoded loader that collects information about the host computer after installation. HexEval selectively deploys another malicious program named BeaverTail, which can download and run a Python-based backdoor called InvisibleFerret. This sequence allows the Hackers to steal sensitive data and remotely control the infected system. “This nesting-doll structure helps the campaign evade basic static scanners and manual reviews,” stated Socket researcher Kirill Boychenko.

The campaign often begins when threat actors pose as recruiters on platforms like LinkedIn. They contact software engineers and send fake job assignments via links to projects hosted on GitHub or Bitbucket where these npm packages are embedded. Victims are then convinced to download and run these projects, sometimes outside of secure environments.

The Contagious Interview operation, first detailed by Palo Alto Networks Unit 42 in late 2023, seeks unauthorized access to developer machines primarily for cryptocurrency and data theft. The campaign is also known by names like CL-STA-0240, DeceptiveDevelopment, and Gwisin Gang.

- Advertisement -

Socket reports that current attacker tactics combine malware-laced open source packages, tailored social engineering, and layered delivery mechanisms to bypass security systems. The campaign shows ongoing refinement, with the addition of cross-platform keyloggers and new malware delivery techniques.

Recent activity includes the use of a social engineering strategy called ClickFix, which delivers malware such as GolangGhost and PylangGhost. This sub-campaign, ClickFake Interview, continues to target developers with customized payloads for deeper surveillance when necessary.

More details and the full list of affected npm packages can be found through the public statement by Socket.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Google releases fast AI; OpenAI previews ultrafast

Google launched Gemini 3.7 Flash on Thursday, a low-cost model for coding and agents,...

Trezor data leak exposes 13,689 customers to phishing risks

A data breach at Trezor's shipping partner ShipMonk leaked personal details of 13,689 customers...

Public miners cut capacity faster than network, shift to AI

A cohort of public Bitcoin miners reduced realized hashrate by 13.4% from Q4 2025...

SNDK’s Wild Ride: Next Stop $2K or $1K?

SanDisk stock (NASDAQ: SNDK) hit a yearly high of $2,354 before plunging to $985,...

UK regulator HTX in settlement talks over illegal crypto ads

Britain's Financial Conduct Authority and HTX are in talks to settle the regulator's claim...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading