THREAT ACTOR INTELLIGENCE REPORT

North Korean Contagious Interview Campaign Abuses Developer Tools for Malware Delivery

Analysis of a North Korean Cybercrime Operation Leveraging GitHub Repositories, VS Code Projects, Malicious Extensions, and Supply Chain Attacks to Target Developers Worldwide

Analyst
Rajkumar G
Date
17 June 2026
Classification
Public
Report Type
Threat Actor Intelligence

Executive Summary

Proofpoint researchers identified a large-scale campaign attributed to a North Korean threat cluster known as Contagious Interview. The operation targets software developers using fake recruitment opportunities, code review requests, malicious GitHub repositories, and weaponized developer tools. The threat actor distributes malware through Visual Studio Code projects, malicious VS Code extensions, npm packages, Git hooks, cryptocurrency-related repositories, and software supply chain compromises. The primary objective is credential theft, cryptocurrency theft, and financial gain.

Key Intelligence Overview

Threat Actor

Contagious Interview

Origin

North Korea

Motivation

Financial Gain

Severity

Critical

Primary Targets

Developers

Confidence

High

Threat Actor Profile

Contagious Interview is a North Korean cybercrime operation known for targeting developers through fake job interviews, coding assessments, open-source projects, and software repositories. The actor has evolved from social engineering on LinkedIn into large-scale phishing operations delivered through email campaigns and malicious development resources.

Known Aliases

Targeted Industries

Campaign Timeline

2024

Fake developer recruitment campaigns observed.

2025

VS Code project abuse and malicious repositories increase.

December 2025

Adoption of VS Code runOn:folderOpen execution technique.

May 2026

Campaign shifts to open-source code review themes.

June 2026

Proofpoint publicly reports UNK_DeadDrop campaign.

Attack Chain Analysis

Initial Access

Victims receive phishing emails containing links to malicious GitHub repositories disguised as technical assignments or cryptocurrency projects.

Execution

Opening the repository inside Visual Studio Code triggers automatic execution through the runOn:folderOpen feature.

Persistence

Malicious VS Code extensions establish long-term access and enable remote command execution.

Credential Access

The malware steals browser credentials, wallet information, developer secrets, and authentication tokens.

Collection

Sensitive files, cryptocurrency wallet data, SSH keys, cloud configurations, and development credentials are collected.

Exfiltration

Collected data is transmitted to attacker-controlled infrastructure through HTTP POST requests and cloud-based command channels.

Malware Families Observed

MITRE ATT&CK Mapping

Tactic Observed Activity
Initial Access Phishing via GitHub Repositories
Execution VS Code Auto Execution
Persistence Malicious Extensions
Credential Access Credential Harvesting
Collection Wallet Data Theft
Command & Control HTTP & Cloud APIs
Exfiltration Data Transfer to C2 Servers

Indicators of Interest

Detection Opportunities

Defensive Recommendations

  1. Verify technical assignments before execution.
  2. Disable automatic VS Code task execution where possible.
  3. Review third-party extensions before installation.
  4. Use MFA for developer accounts.
  5. Implement software supply chain security controls.
  6. Monitor repository modifications and commits.
  7. Conduct threat hunting for malicious developer tooling.

Analyst Assessment

Contagious Interview represents one of the most advanced developer-focused cybercrime operations currently active. The group's ability to weaponize software development workflows, open-source ecosystems, IDEs, package managers, and recruitment processes demonstrates a highly adaptive threat model. Organizations employing developers, DevOps engineers, blockchain engineers, and software architects should consider this threat actor a high-priority risk.

References

Share Report