DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning — Threadlinqs Intelligence
As of 2026-05-30, DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning is a high-severity supply chain threat attributed to Lazarus Group (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-0332 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: Lazarus Group · North Korea · FINANCIAL
North Korean Lazarus Group operates the Contagious Interview campaign, publishing 1,700+ malicious packages across npm, PyPI, Go, Rust, and PHP ecosystems. The campaign uses fake job recruitment lures
The Contagious Interview campaign is a persistent, multi-ecosystem software supply chain attack operated by DPRK-linked threat actors under the Lazarus Group umbrella (tracked as Jade Sleet, TraderTraitor, UNC4899, Famous Chollima, and Tenacious Pungsan). Active since at least mid-2024 and intensifying through 2026, the operation has published over 1,700 malicious packages across npm, PyPI, Go, Rust, and PHP registries, accumulating more than 50,000 downloads.
The attack chain begins with social engineering: operators create fake recruiter personas on LinkedIn, Facebook, Reddit, and job boards (Freelancer.com, Upwork, CryptoJobsList), impersonating hiring managers from cryptocurrency, blockchain, and AI companies. Victims — typically software developers and Web3 engineers — are directed to clone GitHub or Bitbucket repositories containing coding assessments. These repositories include malicious dependencies that trigger upon npm install or pip install.
Three front companies were established to support the campaign: BlockNovas LLC (blocknovas.com), Angeloper Agency (angeloper.com), and SoftGlide LLC (softglide.co), all registered with fabricated addresses and AI-generated employee profile photos created via remaker.ai.
The malware delivery chain employs multiple loader families. The HexEval loader uses hex-encoded strings to evade static analysis, decoding module names and C2 URLs at runtime before issuing HTTPS POST requests to retrieve second-stage payloads via eval(). The XORIndex loader and encrypted loaders reconstruct malicious code directly in memory to bypass disk-based detection. Lifecycle hooks (postinstall) in npm packages serve as the initial execution trigger.
The primary malware families include:
1. BeaverTail — A JavaScript-based infostealer and downloader. It scans approximately 200 browser profile directories for cookies and IndexedDB files, targets cryptocurrency wallets (Solana id.json, Exodus, MetaMask, and 24+ browser extension wallets), extracts macOS Login Keychain data, and downloads the next-stage payload.
2. InvisibleFerret — A cross-platform Python-based RAT downloaded from C2 servers via URL pattern http://<C2>:1224/client/3/<campaign_id>. Capabilities include persistent remote command execution, file manipulation, process enumeration, and data exfiltration to C2 upload endpoints.
3. OtterCookie — A JavaScript-based backdoor first observed in September 2024, evolved into a modular platform with VM detection, socket.io-based C2 communication, data exfiltration, and arbitrary shell command execution.
4. FrostyFerret — A Golang backdoor with hardcoded C2 configuration used in later campaign waves.
Additional capabilities observed include cross-platform keyloggers (WinKeyServer, MacKeyServer, X11KeyServer) deployed via the jsonsecs package variant, screenshot capture, clipboard monitoring, mouse/keyboard remote control, and SSH/GPG/AWS credential theft.
C2 infrastructure leverages a mix of Vercel-hosted API endpoints for initial beaconing (log-server-lovat.vercel.app, ip-check-server.vercel.app), raw IP addresses on commodity VPS providers (RouterHosting/Cloudzy AS14956, Hetzner, TheHosting/WorkTitans), and legitimate services (Bitbucket, jsonkeeper.com paste service). Characteristic port signatures include 1224, 1244, 5918, 5934, 5961, and 5974 — any server presenting these simultaneously is assessed as Lazarus infrastructure.
The campaign has been attributed with high confidence to DPRK state-sponsored actors based on infrastructure overlaps with previously documented Lazarus operations, the use of Astrill VPN (documented as DPRK's VPN of choice with 19 Astrill VPN IPs found in victim logs), persona connections to known Lazarus operators, token-based C2 communication patterns matching 2023 Jade Sleet campaigns, and OPSEC failures exposing monitoring dashboards tracking campaign infrastructure.
Weaknesses (CWE)
CWE-506, CWE-829, CWE-494, CWE-502
Target sectors: technology, cryptocurrency, blockchain, financial, software-development, web3, artificial-intelligence
Target regions: North America, Europe, Asia-Pacific, Global
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1608, T1585, T1195, T1566, T1199, T1204, T1059, T1059, T1202, T1547