Threat reportMalwareTL-2026-1511

DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and INVISIBLEFERRET via Blockchain Smart Contracts

highACTIVE

DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and (TL-2026-1511), also tracked as Contagious Interview, is a high-severity malware campaign, first published 2026-07-19. It is attributed to UNC5342 (North Korea) with high confidence, affects npm npm registry packages (typosquatted developer tooling), maps to 28 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
28MITRE ATT&CK
Actors
1UNC5342
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-1511

Threat ID
TL-2026-1511
Also known as
Contagious Interview, EtherHiding (DPRK adoption)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UNC5342
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
FINANCIAL
Target sectors
technology, cryptocurrency, finance, software development, gaming web3
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
23

Malware and tooling in DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and

Malware and tooling: BeaverTail - S1246, HexEval Loader - S1249, InvisibleFerret - S1245, JADESNOW, OtterCookie

How DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and works

Google Threat Intelligence Group (GTIG) reports that North Korea-linked UNC5342, operating within the 'Contagious Interview' campaign active since February 2025, is the first observed nation-state actor to adopt EtherHiding — hosting malicious JavaScript payloads in BNB Smart Chain and Ethereum smart contracts and retrieving them via read-only eth_call requests to evade takedown.

UNC5342, a North Korea (DPRK) state-sponsored threat cluster operating the long-running 'Contagious Interview' social-engineering campaign (also tracked as CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, and Void Dokka), has become the first nation-state actor observed adopting EtherHiding — a technique first documented in September/October 2023 by Guardio Labs against the financially motivated CLEARFAKE campaign run by UNC5142. EtherHiding embeds malicious JavaScript payloads inside smart contracts deployed on BNB Smart Chain and Ethereum, retrieved via read-only eth_call requests that create no visible transaction and incur no gas fees, giving attackers a decentralized, effectively unseizable hosting layer for C2 and payload delivery. UNC5342 lures software and cryptocurrency developers through fake recruiter personas on LinkedIn and job boards, impersonating shell companies (BlockNovas LLC, Angeloper Agency, SoftGlideLLC), moving the conversation to Telegram or Discord, and requesting a 'technical assessment' that requires the victim to clone and run a GitHub repository or npm package, or to fix a fake ClickFix video-call error by running attacker-supplied code. The resulting infection chain runs a JavaScript downloader (JADESNOW, evolved from the HexEval Loader lineage) that queries BNB Smart Chain/Ethereum smart contracts via eth_call, decodes Base64/XOR-encrypted payloads in memory, and drops the BEAVERTAIL JavaScript infostealer, which in turn deploys the INVISIBLEFERRET backdoor in both Python and JavaScript variants. BEAVERTAIL and INVISIBLEFERRET together harvest browser-stored credentials, session cookies, payment card data, and cryptocurrency wallet data (MetaMask, Phantom) plus password-manager vaults (1Password), compress the loot into ZIP archives, and exfiltrate it to attacker infrastructure and private Telegram chats. The JavaScript INVISIBLEFERRET variant additionally opens an interactive backdoor over TCP/3306 (masquerading as MySQL) supporting arbitrary command execution and file/directory exfiltration. UNC5342 has also folded this tooling into supply-chain operations, publishing malicious npm packages (including a June 2025 wave compromising React Native Aria/GlueStack-adjacent tooling and a subsequent wave of 35 typosquatted packages such as reactbootstraps and react-plaid-sdk) that pull JADESNOW/BEAVERTAIL at install time. On-chain, GTIG identified a primary BNB Smart Chain contract (0x8eac3198dd72f3e07108c4c7cff43108ad48a71c) updated 20+ times over four months at an average gas cost of $1.37 per update, owned by wallet 0x9bc1355344b54dedf3e44296916ed15653844509, and observed a parallel Ethereum-side 'dead drop resolver' technique (MITRE T1102.001) in which payload data is smuggled as transaction calldata sent to the null/burn address 0x000000000000000000000000000000000000dEaD, making the sender address itself irrelevant to retrieval. UNC5342 retrieves this data through centralized blockchain-explorer APIs (Binplorer, Blockchair, Blockcypher, Ethplorer) for redundancy, in contrast to UNC5142's direct RPC-node approach — a centralization dependency that gives defenders a practical intervention point despite the underlying blockchain's immutability. The campaign's dual objectives are cryptocurrency theft and espionage/persistent access against software and crypto-industry developers, and it remains active as of the October 2025 GTIG disclosure and subsequent 2026 reporting on continued front-company and npm-package waves.

MITRE ATT&CK techniques used in TL-2026-1511

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Exfiltration

T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Execution

T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Command and Control

T1102 Web Service; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1571 Non-Standard Port

Initial Access

T1195.001 Compromise Software Dependencies and Development Tools; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link

initial-access

T1195.002 Compromise Software Supply Chain

Persistence

T1505 Server Software Component

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers

Resource Development

T1583.006 Web Services; T1585.001 Social Media Accounts

Reconnaissance

T1589 Gather Victim Identity Information

Impact

T1657 Financial Theft

Affected products and versions in DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and

  • npm — npm registry packages (typosquatted developer tooling)
    Vulnerable versions: malicious packages including react-plaid-sdk, reactbootstraps, and 35+ typosquats of vite-plugin-*, react-*, *-logger, json*
    Fixed in: N/A - malicious packages removed from registry by npm security team
  • Google Chrome / Enterprise browsers — Browser-stored credentials and extensions
    Vulnerable versions: all versions absent enterprise download/URL restriction policy
    Fixed in: N/A - mitigated via enterprise policy, not a software patch
  • MetaMask / Phantom — Cryptocurrency wallet browser extensions
    Vulnerable versions: all versions - targeted for local credential/keystore theft, not a wallet software vulnerability

Remediation for DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and

Immediate actions

  • Block outbound connections to known blockchain explorer APIs used for payload retrieval where not business-required (binplorer.com, blockchair.com, blockcypher.com, ethplorer.io)
  • Block/alert on the identified malicious BNB Smart Chain contract (0x8eac3198dd72f3e07108c4c7cff43108ad48a71c) and owner wallet (0x9bc1355344b54dedf3e44296916ed15653844509)
  • Block outbound TCP/3306 from developer endpoints to non-database infrastructure to disrupt INVISIBLEFERRET.JAVASCRIPT C2
  • Remove/quarantine identified malicious npm packages and audit recent npm installs for typosquats of react-*, vite-plugin-*, *-logger, json* package families
  • Advise developer staff on Contagious Interview social-engineering pattern: fake recruiters on LinkedIn moving contact to Telegram/Discord and requesting code execution as a 'technical assessment'

Workarounds

  • Enterprise Chrome policy: DownloadRestrictions blocking dangerous file types (.exe, .msi, .bat, .dll)
  • Enterprise Chrome policy: enforce automated silent background updates and train users that manual update prompts are never legitimate
  • Enterprise Chrome policy: URLBlocklist for known malicious domains/blockchain explorer endpoints; enable Enhanced Safe Browsing

Longer-term hardening

  • Deploy EDR with behavioral detection for Base64+XOR-decoded in-memory JavaScript/Python payload execution
  • Enforce code-review sandboxing for any take-home technical assessment code from external recruiters (VM/container, no host credential access)
  • Monitor npm registry package installs for known-malicious authors/publishers tied to Contagious Interview
  • Integrate blockchain threat-intelligence feeds (malicious contract/wallet address lists) into network security controls
  • Deploy browser policy restricting silent update prompts to reduce ClickFix-style fake update social engineering

Timeline of DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and

  • EtherHiding technique first emerges as part of the financially motivated CLEARFAKE campaign attributed to UNC5142, embedding malicious JavaScript in BNB Smart Chain contracts.
  • Guardio Labs publicly documents EtherHiding attacks using Binance Smart Chain contracts to deliver fake browser-update lures.
  • BeaverTail malware resurfaces in malicious npm packages targeting developers, per The Hacker News reporting.
  • UNC5342 begins incorporating EtherHiding into the ongoing Contagious Interview campaign, marking the first nation-state adoption of the technique.
  • North Korean actors deploy BeaverTail malware via 11 additional malicious npm packages.
  • Silent Push reports Contagious Interview creating three new front companies to distribute BeaverTail, InvisibleFerret, and OtterCookie.
  • Software supply-chain attack compromises React Native Aria and GlueStack-adjacent npm packages; a wave of 35 new malicious/typosquatted npm packages (reactbootstraps, react-plaid-sdk, etc.) is identified across 24 publisher accounts.
  • GTIG observes no further UNC5142 CLEARFAKE/EtherHiding activity after this date, suggesting a pause or tactical shift by that (separate, financially motivated) cluster.
  • Google Cloud publishes 'New Group on the Block' detailing UNC5142's EtherHiding-based distribution of Atomic Stealer, Lumma, Rhadamanthys, and Vidar via ~14,000 compromised WordPress pages.
  • Google Threat Intelligence Group publicly discloses UNC5342's adoption of EtherHiding to deliver JADESNOW and INVISIBLEFERRET via blockchain smart contracts, publishing IOCs including the BNB Smart Chain contract and owner wallet.
  • Microsoft Security Blog publishes further detail on the Contagious Interview campaign delivering malware through fake developer job interviews, confirming continued activity.

Sources cited for DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and

Detection coverage for TL-2026-1511

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1511 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats