Threat reportSupply ChainTL-2026-0813
North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDrop
North Korean Threat Actors Weaponize Developer Tools (VS (TL-2026-0813), also tracked as UNK_DeadDrop, is a high-severity supply-chain compromise, first published 2026-06-15. It is attributed to Contagious Interview (North Korea) with high confidence, affects npm (OpenJS Foundation) npm Registry, maps to 25 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 38 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 1Contagious Interview
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 38Indicators of compromise
Key facts for TL-2026-0813
- Threat ID
- TL-2026-0813
- Also known as
- UNK_DeadDrop, Contagious Interview, Contagious Trader, TaskJacker, DEV#POPPER
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- Contagious Interview
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, cryptocurrency, financial, education, software development
- Target regions
- North America, Europe, Asia-Pacific, South America, Middle East
- Detection rules
- 9
- Indicators of compromise
- 38
Malware and tooling in North Korean Threat Actors Weaponize Developer Tools (VS
Malware and tooling: BeaverTail - S1246, InvisibleFerret - S1245, OtterCookie, XORIndex Loader - S1248, Overlord, SharePoint + Microsoft Graph API C2
How North Korean Threat Actors Weaponize Developer Tools (VS works
North Korean state-sponsored clusters (Contagious Interview/Famous Chollima, BlueNoroff, Lazarus) are industrializing developer-targeted supply-chain attacks via malicious GitHub repos, hundreds of trojanized npm packages, and VS Code extensions, using fake-recruitment and code-review lures to deliver cross-platform stealers and backdoors (BeaverTail, InvisibleFerret, OtterCookie, Overlord) that loot cryptocurrency wallets and developer credentials. Proofpoint's UNK_DeadDrop campaign sent ~250 emails over six weeks to ~100 organizations, 75%+ U.S.-based.
Throughout late 2025 into mid-2026, North Korea-aligned threat actors tracked as Contagious Interview (a.k.a. Famous Chollima, HexagonalRodent, Void Dokkaebi, DEV#POPPER) alongside BlueNoroff (Sapphire Sleet, UNC1069) and the broader Lazarus Group have shifted from bespoke social engineering to an industrialized supply-chain malware factory aimed squarely at software developers. The operation blends LinkedIn/X recruiter personas, fake job interviews, trojanized demo/take-home projects, and code-review requests with weaponized open-source ecosystems.
Delivery channels span the full developer toolchain. On npm, researchers documented 67 packages dropping the XORIndex and HexEval loaders (17,000+ downloads, April-July 2025), a 108-package/261-version factory campaign (March 20-April 20, 2026), and a 197-200 package wave delivering new OtterCookie infostealer variants. On VS Code, the actors abuse the editor's tasks.json 'runOn: folderOpen' auto-execution (adopted since December 2025) and publish backdoored extensions masquerading as Jupyter/Markdown developer tools (ByteBinTools.jupyter-powerdev, ToolCraft.jupyter-powertools, OLDev.markdown-mode-devtools) discovered on the official Marketplace on June 9, 2026. On GitHub, the Contagious Trader sub-cluster spread 50+ malicious packages across 100+ repos and planted malicious .githooks/pre-commit hooks. Packagist (PHP) and the Arch Linux AUR (400+ hijacked packages) were also abused.
The malware stack is cross-platform and modular. BeaverTail (JavaScript downloader/stealer) targets browser wallet extensions and Keychain/credential stores and stages InvisibleFerret, a Python backdoor that has migrated from readable scripts to Cython-compiled .pyd/.so binaries. OtterCookie (now v4, with VM/sandbox detection) is an infostealer flooded across npm. Newer tooling includes custom variants of the open-source Overlord Go framework, the DEV#POPPER multi-stage obfuscated JavaScript RAT, ClipViper (Windows clipboard stealer), and a SharePoint/Microsoft Graph API-based C2 that uses cloud storage as a command queue and exfiltration channel. Collection targets cryptocurrency wallets (desktop and browser), SSH keys, Telegram Desktop sessions, cloud configuration, and environment variables. Expel/Marcus Hutchins reporting ties the activity to $12M in crypto theft in Q1 2026 and 26,584 wallets exfiltrated from 2,726 infected developer systems. Heavy existing sanctions on the DPRK mean financially motivated cybercrime carries little marginal deterrence while funding the regime.
MITRE ATT&CK techniques used in TL-2026-0813
Collection
T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data; T1119 Automated Collection
Defense Evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery
Initial Access
T1195 Supply Chain Compromise; T1566 Phishing
Persistence
T1546 Event Triggered Execution
Credential Access
T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Resource Development
T1585 Establish Accounts; T1608 Stage Capabilities
Impact
Affected products and versions in North Korean Threat Actors Weaponize Developer Tools (VS
- npm (OpenJS Foundation) — npm Registry
Vulnerable versions: public registry packages - Microsoft — Visual Studio Code / Cursor (Marketplace extensions + tasks.json)
Vulnerable versions: all (abuse of legitimate features) - GitHub — GitHub repositories / git hooks
Vulnerable versions: malicious repos and .githooks - Packagist — Packagist (PHP/Composer registry)
Vulnerable versions: public packages - Arch Linux — Arch User Repository (AUR)
Vulnerable versions: 400+ hijacked packages
Remediation for North Korean Threat Actors Weaponize Developer Tools (VS
Immediate actions
- Block C2 IOC 23.137.105.75 (port 5173) and 144.217.86.88 at the perimeter
- Block the 144.172.0.0 and 107.189.22.20 OtterCookie exfil ranges and the *.vercel.app C2 hostnames
- Remove the malicious VS Code extensions ByteBinTools.jupyter-powerdev, ToolCraft.jupyter-powertools, and OLDev.markdown-mode-devtools and audit Marketplace install history
- Purge the listed malicious npm packages from lockfiles and caches; rotate any credentials present on affected developer hosts
Workarounds
- Open untrusted repositories in VS Code Restricted Mode or a disposable VM
- Treat recruiter take-home projects and code-review asks as untrusted; never run them on a primary developer workstation
Longer-term hardening
- Deploy EDR with behavioral detection for VS Code/IDE-spawned shell, VBScript, and node processes
- Enforce dependency all-listing, pinning, and provenance/signature verification in CI
- Disable VS Code tasks.json runOn:folderOpen auto-execution and run untrusted repos in restricted/sandboxed workspaces
Weaknesses (CWE) in North Korean Threat Actors Weaponize Developer Tools (VS
Timeline of North Korean Threat Actors Weaponize Developer Tools (VS
- Socket documents 67 Contagious Interview npm packages dropping XORIndex and HexEval loaders (17,000+ downloads, active April-July 2025).
- S2 Grupo LAB52 details Lazarus Group 'Dream Job' attacks, part of the broader DPRK developer-targeting tradecraft.
- Contagious Interview adopts VS Code tasks.json 'runOn: folderOpen' auto-execution to trigger malware when a cloned repo is opened.
- Microsoft Security Blog publishes 'Contagious Interview: Malware delivered through fake developer job interviews.'
- Start of a 31-day npm malware-factory campaign: 108 malicious packages across 261 versions (through April 20, 2026).
- Panther tracks an OtterCookie infostealer campaign across npm (bjs-lint-builders et al.) with base91-like custom encoding.
- Campaign pivots to requesting open-source project / code reviews as a delivery lure.
- Yeeth Security discovers backdoored VS Code extensions (Jupyter/Markdown lures) live on the official Marketplace.
- Reporting (Security Affairs, HackRead, SC Media) covers ~197-200 npm packages delivering new OtterCookie variants.
- Proofpoint (Saher Naumaan, Carlos Rubio) reports the UNK_DeadDrop campaign: ~250 emails over six weeks to ~100 orgs, 75%+ U.S.-based.
Sources cited for North Korean Threat Actors Weaponize Developer Tools (VS
- North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
- Contagious Interview Campaign Escalates With 67 Malicious npm Packages (XORIndex/HexEval)
- Tracking an OtterCookie Infostealer Campaign Across npm
- Contagious Interview campaign expands with 197 npm packages spreading new OtterCookie malware
- NK Hackers Push 200 Malicious npm Packages with OtterCookie Malware
- Contagious Interview: Malware delivered through fake developer job interviews (Microsoft Security Blog)
- Hunting North Korea's State-Sponsored Contagious Interview Operation (SANS)
- Illicit npm packages deploy new OtterCookie malware variant (SC Media)
- New wave of 'fake interviews' use 35 npm packages to spread malware (BleepingComputer)
- North Korea's Contagious Interview Malware Floods npm With 200 New Packages (Security Buzz)
Detection coverage for TL-2026-0813
As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0813 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.