Analysis of a North Korean Cybercrime Operation Leveraging GitHub Repositories, VS Code Projects, Malicious Extensions, and Supply Chain Attacks to Target Developers Worldwide
Proofpoint researchers identified a large-scale campaign attributed to a North Korean threat cluster known as Contagious Interview. The operation targets software developers using fake recruitment opportunities, code review requests, malicious GitHub repositories, and weaponized developer tools. The threat actor distributes malware through Visual Studio Code projects, malicious VS Code extensions, npm packages, Git hooks, cryptocurrency-related repositories, and software supply chain compromises. The primary objective is credential theft, cryptocurrency theft, and financial gain.
Contagious Interview
North Korea
Financial Gain
Critical
Developers
High
Contagious Interview is a North Korean cybercrime operation known for targeting developers through fake job interviews, coding assessments, open-source projects, and software repositories. The actor has evolved from social engineering on LinkedIn into large-scale phishing operations delivered through email campaigns and malicious development resources.
Fake developer recruitment campaigns observed.
VS Code project abuse and malicious repositories increase.
Adoption of VS Code runOn:folderOpen execution technique.
Campaign shifts to open-source code review themes.
Proofpoint publicly reports UNK_DeadDrop campaign.
Victims receive phishing emails containing links to malicious GitHub repositories disguised as technical assignments or cryptocurrency projects.
Opening the repository inside Visual Studio Code triggers automatic execution through the runOn:folderOpen feature.
Malicious VS Code extensions establish long-term access and enable remote command execution.
The malware steals browser credentials, wallet information, developer secrets, and authentication tokens.
Sensitive files, cryptocurrency wallet data, SSH keys, cloud configurations, and development credentials are collected.
Collected data is transmitted to attacker-controlled infrastructure through HTTP POST requests and cloud-based command channels.
| Tactic | Observed Activity |
|---|---|
| Initial Access | Phishing via GitHub Repositories |
| Execution | VS Code Auto Execution |
| Persistence | Malicious Extensions |
| Credential Access | Credential Harvesting |
| Collection | Wallet Data Theft |
| Command & Control | HTTP & Cloud APIs |
| Exfiltration | Data Transfer to C2 Servers |
Contagious Interview represents one of the most advanced developer-focused cybercrime operations currently active. The group's ability to weaponize software development workflows, open-source ecosystems, IDEs, package managers, and recruitment processes demonstrates a highly adaptive threat model. Organizations employing developers, DevOps engineers, blockchain engineers, and software architects should consider this threat actor a high-priority risk.