DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning
DPRK Contagious Interview Supply Chain RAT Campaign via npm (TL-2026-0332), also tracked as Contagious Interview, is a high-severity supply-chain compromise, first published 2026-04-07. It is attributed to Lazarus Group (North Korea) with high confidence, affects npm npm Registry, maps to 25 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 35 indicators of compromise.
Key facts for TL-2026-0332
- Threat ID
- TL-2026-0332
- Also known as
- Contagious Interview, Operation Contagious Interview, Tenacious Pungsan, DEV#POPPER
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-04-07
- Last reviewed
- 2026-04-07
- Attribution
- Lazarus Group
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, cryptocurrency, blockchain, financial, software-development, web3, artificial-intelligence
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 35
Malware and tooling in DPRK Contagious Interview Supply Chain RAT Campaign via npm
Malware and tooling: Bada Stealer, BeaverTail - S1246, FrostyFerret, HexEval, InvisibleFerret - S1245, OtterCookie, XORIndex
North Korean Lazarus Group operates the Contagious Interview campaign, publishing 1,700+ malicious packages across npm, PyPI, Go, Rust, and PHP ecosystems. The campaign uses fake job recruitment lures to trick developers into executing trojanized packages that deploy BeaverTail infostealer, InvisibleFerret RAT, and OtterCookie backdoor for persistent access, credential theft, and cryptocurrency wallet exfiltration.
How DPRK Contagious Interview Supply Chain RAT Campaign via npm works
The Contagious Interview campaign is a persistent, multi-ecosystem software supply chain attack operated by DPRK-linked threat actors under the Lazarus Group umbrella (tracked as Jade Sleet, TraderTraitor, UNC4899, Famous Chollima, and Tenacious Pungsan). Active since at least mid-2024 and intensifying through 2026, the operation has published over 1,700 malicious packages across npm, PyPI, Go, Rust, and PHP registries, accumulating more than 50,000 downloads.
The attack chain begins with social engineering: operators create fake recruiter personas on LinkedIn, Facebook, Reddit, and job boards (Freelancer.com, Upwork, CryptoJobsList), impersonating hiring managers from cryptocurrency, blockchain, and AI companies. Victims — typically software developers and Web3 engineers — are directed to clone GitHub or Bitbucket repositories containing coding assessments. These repositories include malicious dependencies that trigger upon npm install or pip install.
Three front companies were established to support the campaign: BlockNovas LLC (blocknovas.com), Angeloper Agency (angeloper.com), and SoftGlide LLC (softglide.co), all registered with fabricated addresses and AI-generated employee profile photos created via remaker.ai.
The malware delivery chain employs multiple loader families. The HexEval loader uses hex-encoded strings to evade static analysis, decoding module names and C2 URLs at runtime before issuing HTTPS POST requests to retrieve second-stage payloads via eval(). The XORIndex loader and encrypted loaders reconstruct malicious code directly in memory to bypass disk-based detection. Lifecycle hooks (postinstall) in npm packages serve as the initial execution trigger.
The primary malware families include:
1. BeaverTail — A JavaScript-based infostealer and downloader. It scans approximately 200 browser profile directories for cookies and IndexedDB files, targets cryptocurrency wallets (Solana id.json, Exodus, MetaMask, and 24+ browser extension wallets), extracts macOS Login Keychain data, and downloads the next-stage payload.
2. InvisibleFerret — A cross-platform Python-based RAT downloaded from C2 servers via URL pattern http://<C2>:1224/client/3/<campaign_id>. Capabilities include persistent remote command execution, file manipulation, process enumeration, and data exfiltration to C2 upload endpoints.
3. OtterCookie — A JavaScript-based backdoor first observed in September 2024, evolved into a modular platform with VM detection, socket.io-based C2 communication, data exfiltration, and arbitrary shell command execution.
4. FrostyFerret — A Golang backdoor with hardcoded C2 configuration used in later campaign waves.
Additional capabilities observed include cross-platform keyloggers (WinKeyServer, MacKeyServer, X11KeyServer) deployed via the jsonsecs package variant, screenshot capture, clipboard monitoring, mouse/keyboard remote control, and SSH/GPG/AWS credential theft.
C2 infrastructure leverages a mix of Vercel-hosted API endpoints for initial beaconing (log-server-lovat.vercel.app, ip-check-server.vercel.app), raw IP addresses on commodity VPS providers (RouterHosting/Cloudzy AS14956, Hetzner, TheHosting/WorkTitans), and legitimate services (Bitbucket, jsonkeeper.com paste service). Characteristic port signatures include 1224, 1244, 5918, 5934, 5961, and 5974 — any server presenting these simultaneously is assessed as Lazarus infrastructure.
The campaign has been attributed with high confidence to DPRK state-sponsored actors based on infrastructure overlaps with previously documented Lazarus operations, the use of Astrill VPN (documented as DPRK's VPN of choice with 19 Astrill VPN IPs found in victim logs), persona connections to known Lazarus operators, token-based C2 communication patterns matching 2023 Jade Sleet campaigns, and OPSEC failures exposing monitoring dashboards tracking campaign infrastructure.
MITRE ATT&CK techniques used in TL-2026-0332
collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection
defense-evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
exfiltration
T1041 Exfiltration Over C2 Channel
execution
T1059 Command and Scripting Interpreter; T1204 User Execution
command-and-control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
discovery
T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery
initial-access
T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
stealth
T1202 Indirect Command Execution
persistence
T1547 Boot or Logon Autostart Execution
credential-access
T1555 Credentials from Password Stores
resource-development
T1585 Establish Accounts; T1608 Stage Capabilities
impact
Affected products and versions in DPRK Contagious Interview Supply Chain RAT Campaign via npm
- npm — npm Registry
Vulnerable versions: Multiple typosquatted packages including react-plaid-sdk, sumsub-node-websdk, vite-plugin-next-refresh, graphalgo, graphflux, eslint-detector, express-session-js, duer-js, passports-js, bcrypts-js, blockscan-api, and 1700+ others
Fixed in: Packages removed upon detection — ongoing whack-a-mole - PyPI — PyPI Registry
Vulnerable versions: graphalgo, graphex, graphlibx, graphdict, graphflux, graphnode, graphsync, bigpyx, bignum, bigmathex, bigmathix, bigmathutils
Fixed in: Packages removed upon detection - Multiple — Go, Rust, PHP Registries
Vulnerable versions: Various typosquatted packages across ecosystems
Fixed in: Ongoing removal
Remediation for DPRK Contagious Interview Supply Chain RAT Campaign via npm
Immediate actions
- Audit all npm and PyPI dependencies for known malicious Contagious Interview packages
- Block C2 IPs at perimeter: 172.86.80.145, 95.164.17.24, 95.216.37.186, 216.126.237.71, 37.221.126.117, 86.104.74.169
- Block C2 domains: lianxinxiao.com, blocknovas.com, angeloper.com, softglide.co, camdriversupport.com, easydriver.cloud, apply-blocknovas.site
- Block Vercel-hosted C2 endpoints: log-server-lovat.vercel.app, ip-check-server.vercel.app, ip-check-api.vercel.app
- Search for PID files at ~/.npm-compiler/ and temp directories at ~/.npm-cache/__tmp__/ indicating active RAT infections
- Check for unauthorized socket.io-client, screenshot-desktop, clipboardy, @nut-tree-fork/nut-js, sharp global npm installations
Workarounds
- Run coding assessments in isolated Docker containers or VMs with no network access to sensitive resources
- Verify recruiter identities through official company HR channels before executing any code
- Use npm audit and socket.dev to scan dependencies before installation
Longer-term hardening
- Implement package lockfile integrity verification in CI/CD pipelines
- Deploy software composition analysis (SCA) tools to detect typosquatting and dependency confusion
- Enforce code review policies for all third-party dependency additions
- Monitor for outbound connections to ports 1224, 1244, 5918, 5934, 5961, 5974
- Implement developer security awareness training focused on social engineering via fake job offers
- Use sandboxed environments for evaluating coding assessments from unknown recruiters
- Deploy EDR with behavioral detection for eval()-based payload execution and in-memory code reconstruction
Weaknesses (CWE) in DPRK Contagious Interview Supply Chain RAT Campaign via npm
CWE-506, CWE-829, CWE-494, CWE-502
Timeline of DPRK Contagious Interview Supply Chain RAT Campaign via npm
- BlockNovas LLC front company domain registered via NameCheap with fabricated address at 2001 Augusta Rd, Warrenville, SC 29851
- OtterCookie JavaScript backdoor first observed in the wild, initially as a basic remote command execution tool
- Contagious Interview campaign first publicly documented with initial HexEval Loader packages (cln-logger, node-clog) identified on npm
- Major expansion wave: 35 new malicious npm packages across 24 accounts deployed, introducing HexEval, XORIndex, and encrypted loader families
- Unit42 publishes detailed analysis of BeaverTail and InvisibleFerret malware families targeting tech job seekers
- 338 malicious npm packages linked to campaign identified, with over 50,000 cumulative downloads documented across the ecosystem
- Datadog Security Labs publishes Tenacious Pungsan report confirming DPRK attribution via C2 overlap with previously documented Lazarus infrastructure at 95.164.17.24:1224
- Silent Push exposes three front companies (BlockNovas, Angeloper Agency, SoftGlide) used as recruitment facades with AI-generated employee profiles
- Google Cloud Threat Intel reports DPRK-nexus actor targeting the legitimate Axios npm package ecosystem
- Campaign confirmed active across npm, PyPI, Go, Rust, and PHP ecosystems with graphalgo operation deploying 24 npm + 12 PyPI packages simultaneously
- Microsoft Security Blog publishes comprehensive analysis documenting OtterCookie and FlexibleFerret variants stealing API tokens, cloud credentials, and source code
- Socket Security identifies 35 additional malicious npm packages with 4,000+ downloads, six still live on registry at time of publication
- SafeDep discovers express-session-js typosquat dropping full RAT payload with screen capture, keyboard/mouse control, and credential theft via C2 at 216.126.237.71
- Campaign remains actively publishing new packages with scale exceeding 1,700 malicious packages. New packages continue to appear across multiple registries
- As of 2026-05-29, this DPRK Contagious Interview supply-chain campaign remains highly active and intensifying, with April 2026 reporting confirming 1,700+ malicious npm/PyPI/Go/Rust/PHP packages, an evolved OtterCookie/BeaverTail variant, and new GitHub/Vercel/Pastebin dead-drop C2. No takedown or actor disruption occurred; ~$12M in crypto was stolen from 2,726 infected developers in early 2026.
Sources cited for DPRK Contagious Interview Supply Chain RAT Campaign via npm
- Socket: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages
- The Hacker News: Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems
- SafeDep: Malicious npm Package express-session-js Drops Full RAT Payload
- Microsoft: Contagious Interview — Malware Delivered Through Fake Developer Job Interviews
- Google Cloud: North Korea-Nexus Threat Actor Compromises Axios NPM Package
- Datadog Security Labs: Tenacious Pungsan — DPRK Contagious Interview
- eSecurity Planet: 338 Malicious npm Packages Linked to North Korean Hackers
- Silent Push: Contagious Interview Creates Three Front Companies to Deliver Malware
- Unit42: North Korean Threat Actors Lure Tech Job Seekers with BeaverTail and InvisibleFerret
- SANS: Hunting North Korea's State-Sponsored Contagious Interview Operation
- Breakglass Intel: Mapping DPRK Contagious Interview From InvisibleFerret to Kimsuky Crossover
- Recorded Future: PurpleBravo's Targeting of the IT Software Supply Chain
Threats related to DPRK Contagious Interview Supply Chain RAT Campaign via npm
- Contagious Interview: DPRK Campaign Delivers OtterCookie and FlexibleFerret Backdoors via Fake Developer Job Interviews
- Void Dokkaebi (Famous Chollima) Cython-Compiled InvisibleFerret — .pyd/.so Binary Evasion of Script-Based Detections (DPRK Contagious Interview)
- Lazarus-Linked npm Malware Masquerades as Rollup Polyfills (rollup-packages-polyfill-core, rollup-runtime-polyfill-core, swift-parse-stream, quirky-token, rollup-plugin-polyfill-connect, react-icon-svgs)
- Lazarus Group npm Brandjacking Campaign — buffer-utilities Multi-Stage Staging Framework (sonatype-2026-003558)
- Supply Chain Attacks on Crypto Ecosystem via Developer Toolchain Compromise
- PolinRider Campaign: North Korea-Linked Supply Chain Attack Expands Across npm, Packagist, Go Modules, and Chrome Web Store (DEV#POPPER / OmniStealer)
Detection coverage for TL-2026-0332
As of 2026-04-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0332 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.