Threat reportSupply ChainTL-2026-0813

North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDrop

highACTIVE

North Korean Threat Actors Weaponize Developer Tools (VS (TL-2026-0813), also tracked as UNK_DeadDrop, is a high-severity supply-chain compromise, first published 2026-06-15. It is attributed to Contagious Interview (North Korea) with high confidence, affects npm (OpenJS Foundation) npm Registry, maps to 25 MITRE ATT&CK techniques (T1005, T1014, T1027), and is covered by 9 detection rules and 38 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
25MITRE ATT&CK
Actors
1Contagious Interview
Detection rules
9SPL · KQL · Sigma
IOCs
38Indicators of compromise

Key facts for TL-2026-0813

Threat ID
TL-2026-0813
Also known as
UNK_DeadDrop, Contagious Interview, Contagious Trader, TaskJacker, DEV#POPPER
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
Contagious Interview
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, cryptocurrency, financial, education, software development
Target regions
North America, Europe, Asia-Pacific, South America, Middle East
Detection rules
9
Indicators of compromise
38

Malware and tooling in North Korean Threat Actors Weaponize Developer Tools (VS

Malware and tooling: BeaverTail - S1246, InvisibleFerret - S1245, OtterCookie, XORIndex Loader - S1248, Overlord, SharePoint + Microsoft Graph API C2

How North Korean Threat Actors Weaponize Developer Tools (VS works

North Korean state-sponsored clusters (Contagious Interview/Famous Chollima, BlueNoroff, Lazarus) are industrializing developer-targeted supply-chain attacks via malicious GitHub repos, hundreds of trojanized npm packages, and VS Code extensions, using fake-recruitment and code-review lures to deliver cross-platform stealers and backdoors (BeaverTail, InvisibleFerret, OtterCookie, Overlord) that loot cryptocurrency wallets and developer credentials. Proofpoint's UNK_DeadDrop campaign sent ~250 emails over six weeks to ~100 organizations, 75%+ U.S.-based.

Throughout late 2025 into mid-2026, North Korea-aligned threat actors tracked as Contagious Interview (a.k.a. Famous Chollima, HexagonalRodent, Void Dokkaebi, DEV#POPPER) alongside BlueNoroff (Sapphire Sleet, UNC1069) and the broader Lazarus Group have shifted from bespoke social engineering to an industrialized supply-chain malware factory aimed squarely at software developers. The operation blends LinkedIn/X recruiter personas, fake job interviews, trojanized demo/take-home projects, and code-review requests with weaponized open-source ecosystems.

Delivery channels span the full developer toolchain. On npm, researchers documented 67 packages dropping the XORIndex and HexEval loaders (17,000+ downloads, April-July 2025), a 108-package/261-version factory campaign (March 20-April 20, 2026), and a 197-200 package wave delivering new OtterCookie infostealer variants. On VS Code, the actors abuse the editor's tasks.json 'runOn: folderOpen' auto-execution (adopted since December 2025) and publish backdoored extensions masquerading as Jupyter/Markdown developer tools (ByteBinTools.jupyter-powerdev, ToolCraft.jupyter-powertools, OLDev.markdown-mode-devtools) discovered on the official Marketplace on June 9, 2026. On GitHub, the Contagious Trader sub-cluster spread 50+ malicious packages across 100+ repos and planted malicious .githooks/pre-commit hooks. Packagist (PHP) and the Arch Linux AUR (400+ hijacked packages) were also abused.

The malware stack is cross-platform and modular. BeaverTail (JavaScript downloader/stealer) targets browser wallet extensions and Keychain/credential stores and stages InvisibleFerret, a Python backdoor that has migrated from readable scripts to Cython-compiled .pyd/.so binaries. OtterCookie (now v4, with VM/sandbox detection) is an infostealer flooded across npm. Newer tooling includes custom variants of the open-source Overlord Go framework, the DEV#POPPER multi-stage obfuscated JavaScript RAT, ClipViper (Windows clipboard stealer), and a SharePoint/Microsoft Graph API-based C2 that uses cloud storage as a command queue and exfiltration channel. Collection targets cryptocurrency wallets (desktop and browser), SSH keys, Telegram Desktop sessions, cloud configuration, and environment variables. Expel/Marcus Hutchins reporting ties the activity to $12M in crypto theft in Q1 2026 and 26,584 wallets exfiltrated from 2,726 infected developer systems. Heavy existing sanctions on the DPRK mean financially motivated cybercrime carries little marginal deterrence while funding the regime.

MITRE ATT&CK techniques used in TL-2026-0813

Collection

T1005 Data from Local System; T1056 Input Capture; T1115 Clipboard Data; T1119 Automated Collection

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1217 Browser Information Discovery

Initial Access

T1195 Supply Chain Compromise; T1566 Phishing

Persistence

T1546 Event Triggered Execution

Credential Access

T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Resource Development

T1585 Establish Accounts; T1608 Stage Capabilities

Impact

T1657 Financial Theft

Affected products and versions in North Korean Threat Actors Weaponize Developer Tools (VS

  • npm (OpenJS Foundation) — npm Registry
    Vulnerable versions: public registry packages
  • Microsoft — Visual Studio Code / Cursor (Marketplace extensions + tasks.json)
    Vulnerable versions: all (abuse of legitimate features)
  • GitHub — GitHub repositories / git hooks
    Vulnerable versions: malicious repos and .githooks
  • Packagist — Packagist (PHP/Composer registry)
    Vulnerable versions: public packages
  • Arch Linux — Arch User Repository (AUR)
    Vulnerable versions: 400+ hijacked packages

Remediation for North Korean Threat Actors Weaponize Developer Tools (VS

Immediate actions

  • Block C2 IOC 23.137.105.75 (port 5173) and 144.217.86.88 at the perimeter
  • Block the 144.172.0.0 and 107.189.22.20 OtterCookie exfil ranges and the *.vercel.app C2 hostnames
  • Remove the malicious VS Code extensions ByteBinTools.jupyter-powerdev, ToolCraft.jupyter-powertools, and OLDev.markdown-mode-devtools and audit Marketplace install history
  • Purge the listed malicious npm packages from lockfiles and caches; rotate any credentials present on affected developer hosts

Workarounds

  • Open untrusted repositories in VS Code Restricted Mode or a disposable VM
  • Treat recruiter take-home projects and code-review asks as untrusted; never run them on a primary developer workstation

Longer-term hardening

  • Deploy EDR with behavioral detection for VS Code/IDE-spawned shell, VBScript, and node processes
  • Enforce dependency all-listing, pinning, and provenance/signature verification in CI
  • Disable VS Code tasks.json runOn:folderOpen auto-execution and run untrusted repos in restricted/sandboxed workspaces

Weaknesses (CWE) in North Korean Threat Actors Weaponize Developer Tools (VS

CWE-506, CWE-829, CWE-94

Timeline of North Korean Threat Actors Weaponize Developer Tools (VS

  • Socket documents 67 Contagious Interview npm packages dropping XORIndex and HexEval loaders (17,000+ downloads, active April-July 2025).
  • S2 Grupo LAB52 details Lazarus Group 'Dream Job' attacks, part of the broader DPRK developer-targeting tradecraft.
  • Contagious Interview adopts VS Code tasks.json 'runOn: folderOpen' auto-execution to trigger malware when a cloned repo is opened.
  • Microsoft Security Blog publishes 'Contagious Interview: Malware delivered through fake developer job interviews.'
  • Start of a 31-day npm malware-factory campaign: 108 malicious packages across 261 versions (through April 20, 2026).
  • Panther tracks an OtterCookie infostealer campaign across npm (bjs-lint-builders et al.) with base91-like custom encoding.
  • Campaign pivots to requesting open-source project / code reviews as a delivery lure.
  • Yeeth Security discovers backdoored VS Code extensions (Jupyter/Markdown lures) live on the official Marketplace.
  • Reporting (Security Affairs, HackRead, SC Media) covers ~197-200 npm packages delivering new OtterCookie variants.
  • Proofpoint (Saher Naumaan, Carlos Rubio) reports the UNK_DeadDrop campaign: ~250 emails over six weeks to ~100 orgs, 75%+ U.S.-based.

Sources cited for North Korean Threat Actors Weaponize Developer Tools (VS

Detection coverage for TL-2026-0813

As of 2026-06-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0813 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
38 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats