Threat Intelligence / Actor / Contagious Interview - G1052
Contagious Interview - G1052
As of 2026-08-25, Contagious Interview - G1052 is a North Korea (DPRK)-nexus threat actor tracked by Threadlinqs Intelligence across 19 threats spanning supply chain, malware, apt. Also known as DEV#POPPER (PolinRider, deceptivedevelopment, dev#popper, g1052.
Also known as: Contagious Interview - G1052, DEV#POPPER (PolinRider, contagious interview, deceptivedevelopment, dev#popper, g1052, gwisin gang, purplebravo, tag-121, tenacious pungsan, Contagious Interview cluster, DPRK-linked)
Tracked threats
- Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan — CRITICAL
- OTTERCOOKIE Malware Hidden in SVG Flag Images Backdoors Developers via Fake Coding Tests (Contagious Interview / REF9403) — HIGH
- ViteVenom: Blockchain-C2 npm Supply Chain Malware Targets Vite Ecosystem (Sequel to ChainVeil, PolinRider Cluster) — HIGH
- North Korean Contagious Interview Campaign Deploys OtterCookie via SVG Steganography to Steal Developer Credentials — HIGH
- Contagious Interview (DPRK) Uses SVG Steganography to Deliver OTTERCOOKIE/BEAVERTAIL Malware (REF9403) — HIGH
- North Korea-Linked Contagious Interview Actors (REF9403) Hide OtterCookie-Aligned Malware in SVG Flag Images — HIGH
- PolinRider DPRK npm Supply-Chain Loader Uses Blockchain Dead Drops for C2 (BeaverTail/InvisibleFerret) — HIGH
- PolinRider: North Korea-Linked Supply Chain Campaign Expands Across npm, Packagist, Go Modules, and Chrome Extensions — CRITICAL
- North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDrop — HIGH
- Famous Chollima (DPRK) Compromises Packagist Package roberts/leads dev Branch — tailwind.js Node.js Loader Uses TRON/Aptos/BNB Blockchain Dead-Drop C2 (EtherHiding-style) — HIGH
- Void Dokkaebi (Famous Chollima) Cython-Compiled InvisibleFerret — .pyd/.so Binary Evasion of Script-Based Detections (DPRK Contagious Interview) — HIGH
- DPRK npm Supply Chain Attack — terminal-logger-utils Abuses Hugging Face (Lordplay/system-releases) to Deliver Node.js SEA Keylogger/Infostealer/RAT — HIGH
- PolinRider — DPRK Supply-Chain Campaign Compromises 1,951 GitHub Repos via Malicious npm Packages, VS Code tasks.json Auto-Run, and TRON/Aptos/BSC Blockchain Dead-Drop C2 — CRITICAL
- Void Dokkaebi (Contagious Interview / Famous Chollima) — DPRK Fake Job Interview Campaign Delivering BeaverTail, InvisibleFerret, OtterCookie & GolangGhost via Trojanized Code Repositories — HIGH
- ClickFix Social Engineering Campaigns Targeting Windows and macOS via Native System Tools — HIGH
- Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job Interviews — HIGH
- Famous Chollima (DPRK) npm Supply Chain — Pastebin Text Steganography Dead-Drop Resolver, 17 Malicious Packages, Vercel C2 Infrastructure — HIGH
- Contagious Interview IDE Task Hijacking — North Korean BeaverTail/PyLangGhost/GolangGhost via VS Code & Cursor Tasks, GitHub Gist Staging, Developer Targeting — HIGH
- Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed Lures, and Staged JavaScript Execution — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →