# North Korean Threat Actors Weaponize Developer Tools (VS Code, npm, GitHub) for Cross-Platform Malware Delivery — Contagious Interview / UNK_DeadDrop

> North Korean state-sponsored clusters (Contagious Interview/Famous Chollima, BlueNoroff, Lazarus) are industrializing developer-targeted supply-chain attacks via malicious GitHub repos, hundreds of trojanized npm packages, and VS Code extensions, using fake-recruitment and code-review lures to deliver cross-platform stealers and backdoors (BeaverTail, InvisibleFerret, OtterCookie, Overlord) that loot cryptocurrency wallets and developer credentials. Proofpoint's UNK_DeadDrop campaign sent ~250 emails over six weeks to ~100 organizations, 75%+ U.S.-based.

- **Published:** 2026-06-15T00:00:00Z
- **Last reviewed:** 2026-06-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0813
- **ID:** TL-2026-0813
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** Contagious Interview (North Korea)
- **Detections:** 9 · **IOCs:** 38 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Throughout late 2025 into mid-2026, North Korea-aligned threat actors tracked as Contagious Interview (a.k.a. Famous Chollima, HexagonalRodent, Void Dokkaebi, DEV#POPPER) alongside BlueNoroff (Sapphire Sleet, UNC1069) and the broader Lazarus Group have shifted from bespoke social engineering to an industrialized supply-chain malware factory aimed squarely at software developers. The operation blends LinkedIn/X recruiter personas, fake job interviews, trojanized demo/take-home projects, and code-review requests with weaponized open-source ecosystems.

Delivery channels span the full developer toolchain. On npm, researchers documented 67 packages dropping the XORIndex and HexEval loaders (17,000+ downloads, April-July 2025), a 108-package/261-version factory campaign (March 20-April 20, 2026), and a 197-200 package wave delivering new OtterCookie infostealer variants. On VS Code, the actors abuse the editor's tasks.json 'runOn: folderOpen' auto-execution (adopted since December 2025) and publish backdoored extensions masquerading as Jupyter/Markdown developer tools (ByteBinTools.jupyter-powerdev, ToolCraft.jupyter-powertools, OLDev.markdown-mode-devtools) discovered on the official Marketplace on June 9, 2026. On GitHub, the Contagious Trader sub-cluster spread 50+ malicious packages across 100+ repos and planted malicious .githooks/pre-commit hooks. Packagist (PHP) and the Arch Linux AUR (400+ hijacked packages) were also abused.

The malware stack is cross-platform and modular. BeaverTail (JavaScript downloader/stealer) targets browser wallet extensions and Keychain/credential stores and stages InvisibleFerret, a Python backdoor that has migrated from readable scripts to Cython-compiled .pyd/.so binaries. OtterCookie (now v4, with VM/sandbox detection) is an infostealer flooded across npm. Newer tooling includes custom variants of the open-source Overlord Go framework, the DEV#POPPER multi-stage obfuscated JavaScript RAT, ClipViper (Windows clipboard stealer), and a SharePoint/Microsoft Graph API-based C2 that uses cloud storage as a command queue and exfiltration channel. Collection targets cryptocurrency wallets (desktop and browser), SSH keys, Telegram Desktop sessions, cloud configuration, and environment variables. Expel/Marcus Hutchins reporting ties the activity to $12M in crypto theft in Q1 2026 and 26,584 wallets exfiltrated from 2,726 infected developer systems. Heavy existing sanctions on the DPRK mean financially motivated cybercrime carries little marginal deterrence while funding the regime.

## MITRE ATT&CK

- T1608 Stage Capabilities
- T1585 Establish Accounts
- T1195 Supply Chain Compromise
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1546 Event Triggered Execution
- T1027 Obfuscated Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1014 Rootkit
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1217 Browser Information Discovery
- T1005 Data from Local System
- T1119 Automated Collection
- T1115 Clipboard Data
- T1056 Input Capture
- T1071 Application Layer Protocol
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft

## Sources

- [North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels](https://thehackernews.com/2026/06/north-korean-hackers-are-turning.html)
- [Contagious Interview Campaign Escalates With 67 Malicious npm Packages (XORIndex/HexEval)](https://socket.dev/blog/contagious-interview-campaign-escalates-67-malicious-npm-packages)
- [Tracking an OtterCookie Infostealer Campaign Across npm](https://panther.com/blog/tracking-an-ottercookie-infostealer-campaign-across-npm)
- [Contagious Interview campaign expands with 197 npm packages spreading new OtterCookie malware](https://securityaffairs.com/185170/apt/contagious-interview-campaign-expands-with-197-npm-ppackages-spreading-new-ottercookie-malware.html)
- [NK Hackers Push 200 Malicious npm Packages with OtterCookie Malware](https://hackread.com/nk-hackers-npm-packages-ottercookie-malware/)
- [Contagious Interview: Malware delivered through fake developer job interviews (Microsoft Security Blog)](https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/)
- [Hunting North Korea's State-Sponsored Contagious Interview Operation (SANS)](https://www.sans.org/presentations/hunting-north-koreas-state-sponsored-contagious-interview-operation-attacks-on-developers-via-the-software-supply-chain)
- [Illicit npm packages deploy new OtterCookie malware variant (SC Media)](https://www.scworld.com/brief/illicit-npm-packages-deploy-new-ottercookie-malware-variant)
- [New wave of 'fake interviews' use 35 npm packages to spread malware (BleepingComputer)](https://www.bleepingcomputer.com/news/security/new-wave-of-fake-interviews-use-35-npm-packages-to-spread-malware/)
- [North Korea's Contagious Interview Malware Floods npm With 200 New Packages (Security Buzz)](https://securitybuzz.com/cybersecurity-news/north-koreas-contagious-interview-malware-floods-npm-with-200-new-packages/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0813
