DPRK Contagious Interview Supply Chain RAT Campaign via npm, PyPI, and Multi-Ecosystem Package Poisoning

DPRK Contagious Interview Supply Chain RAT Campaign via npm (TL-2026-0332), also tracked as Contagious Interview, is a high-severity supply-chain compromise, first published 2026-04-07. It is attributed to Lazarus Group (North Korea) with high confidence, affects npm npm Registry, maps to 25 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 35 indicators of compromise.

Key facts for TL-2026-0332

Threat ID
TL-2026-0332
Also known as
Contagious Interview, Operation Contagious Interview, Tenacious Pungsan, DEV#POPPER
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-04-07
Last reviewed
2026-04-07
Attribution
Lazarus Group
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, cryptocurrency, blockchain, financial, software-development, web3, artificial-intelligence
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
35

Malware and tooling in DPRK Contagious Interview Supply Chain RAT Campaign via npm

Malware and tooling: Bada Stealer, BeaverTail - S1246, FrostyFerret, HexEval, InvisibleFerret - S1245, OtterCookie, XORIndex

North Korean Lazarus Group operates the Contagious Interview campaign, publishing 1,700+ malicious packages across npm, PyPI, Go, Rust, and PHP ecosystems. The campaign uses fake job recruitment lures to trick developers into executing trojanized packages that deploy BeaverTail infostealer, InvisibleFerret RAT, and OtterCookie backdoor for persistent access, credential theft, and cryptocurrency wallet exfiltration.

How DPRK Contagious Interview Supply Chain RAT Campaign via npm works

The Contagious Interview campaign is a persistent, multi-ecosystem software supply chain attack operated by DPRK-linked threat actors under the Lazarus Group umbrella (tracked as Jade Sleet, TraderTraitor, UNC4899, Famous Chollima, and Tenacious Pungsan). Active since at least mid-2024 and intensifying through 2026, the operation has published over 1,700 malicious packages across npm, PyPI, Go, Rust, and PHP registries, accumulating more than 50,000 downloads.

The attack chain begins with social engineering: operators create fake recruiter personas on LinkedIn, Facebook, Reddit, and job boards (Freelancer.com, Upwork, CryptoJobsList), impersonating hiring managers from cryptocurrency, blockchain, and AI companies. Victims — typically software developers and Web3 engineers — are directed to clone GitHub or Bitbucket repositories containing coding assessments. These repositories include malicious dependencies that trigger upon npm install or pip install.

Three front companies were established to support the campaign: BlockNovas LLC (blocknovas.com), Angeloper Agency (angeloper.com), and SoftGlide LLC (softglide.co), all registered with fabricated addresses and AI-generated employee profile photos created via remaker.ai.

The malware delivery chain employs multiple loader families. The HexEval loader uses hex-encoded strings to evade static analysis, decoding module names and C2 URLs at runtime before issuing HTTPS POST requests to retrieve second-stage payloads via eval(). The XORIndex loader and encrypted loaders reconstruct malicious code directly in memory to bypass disk-based detection. Lifecycle hooks (postinstall) in npm packages serve as the initial execution trigger.

The primary malware families include:

1. BeaverTail — A JavaScript-based infostealer and downloader. It scans approximately 200 browser profile directories for cookies and IndexedDB files, targets cryptocurrency wallets (Solana id.json, Exodus, MetaMask, and 24+ browser extension wallets), extracts macOS Login Keychain data, and downloads the next-stage payload.

2. InvisibleFerret — A cross-platform Python-based RAT downloaded from C2 servers via URL pattern http://<C2>:1224/client/3/<campaign_id>. Capabilities include persistent remote command execution, file manipulation, process enumeration, and data exfiltration to C2 upload endpoints.

3. OtterCookie — A JavaScript-based backdoor first observed in September 2024, evolved into a modular platform with VM detection, socket.io-based C2 communication, data exfiltration, and arbitrary shell command execution.

4. FrostyFerret — A Golang backdoor with hardcoded C2 configuration used in later campaign waves.

Additional capabilities observed include cross-platform keyloggers (WinKeyServer, MacKeyServer, X11KeyServer) deployed via the jsonsecs package variant, screenshot capture, clipboard monitoring, mouse/keyboard remote control, and SSH/GPG/AWS credential theft.

C2 infrastructure leverages a mix of Vercel-hosted API endpoints for initial beaconing (log-server-lovat.vercel.app, ip-check-server.vercel.app), raw IP addresses on commodity VPS providers (RouterHosting/Cloudzy AS14956, Hetzner, TheHosting/WorkTitans), and legitimate services (Bitbucket, jsonkeeper.com paste service). Characteristic port signatures include 1224, 1244, 5918, 5934, 5961, and 5974 — any server presenting these simultaneously is assessed as Lazarus infrastructure.

The campaign has been attributed with high confidence to DPRK state-sponsored actors based on infrastructure overlaps with previously documented Lazarus operations, the use of Astrill VPN (documented as DPRK's VPN of choice with 19 Astrill VPN IPs found in victim logs), persona connections to known Lazarus operators, token-based C2 communication patterns matching 2023 Jade Sleet campaigns, and OPSEC failures exposing monitoring dashboards tracking campaign infrastructure.

MITRE ATT&CK techniques used in TL-2026-0332

collection

T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1115 Clipboard Data; T1119 Automated Collection

defense-evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

exfiltration

T1041 Exfiltration Over C2 Channel

execution

T1059 Command and Scripting Interpreter; T1204 User Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

discovery

T1082 System Information Discovery; T1217 Browser Information Discovery; T1518 Software Discovery

initial-access

T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing

stealth

T1202 Indirect Command Execution

persistence

T1547 Boot or Logon Autostart Execution

credential-access

T1555 Credentials from Password Stores

resource-development

T1585 Establish Accounts; T1608 Stage Capabilities

impact

T1657 Financial Theft

Affected products and versions in DPRK Contagious Interview Supply Chain RAT Campaign via npm

  • npm — npm Registry
    Vulnerable versions: Multiple typosquatted packages including react-plaid-sdk, sumsub-node-websdk, vite-plugin-next-refresh, graphalgo, graphflux, eslint-detector, express-session-js, duer-js, passports-js, bcrypts-js, blockscan-api, and 1700+ others
    Fixed in: Packages removed upon detection — ongoing whack-a-mole
  • PyPI — PyPI Registry
    Vulnerable versions: graphalgo, graphex, graphlibx, graphdict, graphflux, graphnode, graphsync, bigpyx, bignum, bigmathex, bigmathix, bigmathutils
    Fixed in: Packages removed upon detection
  • Multiple — Go, Rust, PHP Registries
    Vulnerable versions: Various typosquatted packages across ecosystems
    Fixed in: Ongoing removal

Remediation for DPRK Contagious Interview Supply Chain RAT Campaign via npm

Immediate actions

  • Audit all npm and PyPI dependencies for known malicious Contagious Interview packages
  • Block C2 IPs at perimeter: 172.86.80.145, 95.164.17.24, 95.216.37.186, 216.126.237.71, 37.221.126.117, 86.104.74.169
  • Block C2 domains: lianxinxiao.com, blocknovas.com, angeloper.com, softglide.co, camdriversupport.com, easydriver.cloud, apply-blocknovas.site
  • Block Vercel-hosted C2 endpoints: log-server-lovat.vercel.app, ip-check-server.vercel.app, ip-check-api.vercel.app
  • Search for PID files at ~/.npm-compiler/ and temp directories at ~/.npm-cache/__tmp__/ indicating active RAT infections
  • Check for unauthorized socket.io-client, screenshot-desktop, clipboardy, @nut-tree-fork/nut-js, sharp global npm installations

Workarounds

  • Run coding assessments in isolated Docker containers or VMs with no network access to sensitive resources
  • Verify recruiter identities through official company HR channels before executing any code
  • Use npm audit and socket.dev to scan dependencies before installation

Longer-term hardening

  • Implement package lockfile integrity verification in CI/CD pipelines
  • Deploy software composition analysis (SCA) tools to detect typosquatting and dependency confusion
  • Enforce code review policies for all third-party dependency additions
  • Monitor for outbound connections to ports 1224, 1244, 5918, 5934, 5961, 5974
  • Implement developer security awareness training focused on social engineering via fake job offers
  • Use sandboxed environments for evaluating coding assessments from unknown recruiters
  • Deploy EDR with behavioral detection for eval()-based payload execution and in-memory code reconstruction

Weaknesses (CWE) in DPRK Contagious Interview Supply Chain RAT Campaign via npm

CWE-506, CWE-829, CWE-494, CWE-502

Timeline of DPRK Contagious Interview Supply Chain RAT Campaign via npm

  • BlockNovas LLC front company domain registered via NameCheap with fabricated address at 2001 Augusta Rd, Warrenville, SC 29851
  • OtterCookie JavaScript backdoor first observed in the wild, initially as a basic remote command execution tool
  • Contagious Interview campaign first publicly documented with initial HexEval Loader packages (cln-logger, node-clog) identified on npm
  • Major expansion wave: 35 new malicious npm packages across 24 accounts deployed, introducing HexEval, XORIndex, and encrypted loader families
  • Unit42 publishes detailed analysis of BeaverTail and InvisibleFerret malware families targeting tech job seekers
  • 338 malicious npm packages linked to campaign identified, with over 50,000 cumulative downloads documented across the ecosystem
  • Datadog Security Labs publishes Tenacious Pungsan report confirming DPRK attribution via C2 overlap with previously documented Lazarus infrastructure at 95.164.17.24:1224
  • Silent Push exposes three front companies (BlockNovas, Angeloper Agency, SoftGlide) used as recruitment facades with AI-generated employee profiles
  • Google Cloud Threat Intel reports DPRK-nexus actor targeting the legitimate Axios npm package ecosystem
  • Campaign confirmed active across npm, PyPI, Go, Rust, and PHP ecosystems with graphalgo operation deploying 24 npm + 12 PyPI packages simultaneously
  • Microsoft Security Blog publishes comprehensive analysis documenting OtterCookie and FlexibleFerret variants stealing API tokens, cloud credentials, and source code
  • Socket Security identifies 35 additional malicious npm packages with 4,000+ downloads, six still live on registry at time of publication
  • SafeDep discovers express-session-js typosquat dropping full RAT payload with screen capture, keyboard/mouse control, and credential theft via C2 at 216.126.237.71
  • Campaign remains actively publishing new packages with scale exceeding 1,700 malicious packages. New packages continue to appear across multiple registries
  • As of 2026-05-29, this DPRK Contagious Interview supply-chain campaign remains highly active and intensifying, with April 2026 reporting confirming 1,700+ malicious npm/PyPI/Go/Rust/PHP packages, an evolved OtterCookie/BeaverTail variant, and new GitHub/Vercel/Pastebin dead-drop C2. No takedown or actor disruption occurred; ~$12M in crypto was stolen from 2,726 infected developers in early 2026.

Sources cited for DPRK Contagious Interview Supply Chain RAT Campaign via npm

Threats related to DPRK Contagious Interview Supply Chain RAT Campaign via npm

Detection coverage for TL-2026-0332

As of 2026-04-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0332 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats