Threat reportMalwareTL-2026-1511
DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and INVISIBLEFERRET via Blockchain Smart Contracts
DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and (TL-2026-1511), also tracked as Contagious Interview, is a high-severity malware campaign, first published 2026-07-19. It is attributed to UNC5342 (North Korea) with high confidence, affects npm npm registry packages (typosquatted developer tooling), maps to 28 MITRE ATT&CK techniques (T1005, T1020, T1027), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 28MITRE ATT&CK
- Actors
- 1UNC5342
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-1511
- Threat ID
- TL-2026-1511
- Also known as
- Contagious Interview, EtherHiding (DPRK adoption)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UNC5342
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- FINANCIAL
- Target sectors
- technology, cryptocurrency, finance, software development, gaming web3
- Target regions
- Global, North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and
Malware and tooling: BeaverTail - S1246, HexEval Loader - S1249, InvisibleFerret - S1245, JADESNOW, OtterCookie
How DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and works
Google Threat Intelligence Group (GTIG) reports that North Korea-linked UNC5342, operating within the 'Contagious Interview' campaign active since February 2025, is the first observed nation-state actor to adopt EtherHiding — hosting malicious JavaScript payloads in BNB Smart Chain and Ethereum smart contracts and retrieving them via read-only eth_call requests to evade takedown.
UNC5342, a North Korea (DPRK) state-sponsored threat cluster operating the long-running 'Contagious Interview' social-engineering campaign (also tracked as CL-STA-0240, DeceptiveDevelopment, DEV#POPPER, Famous Chollima, Gwisin Gang, Tenacious Pungsan, and Void Dokka), has become the first nation-state actor observed adopting EtherHiding — a technique first documented in September/October 2023 by Guardio Labs against the financially motivated CLEARFAKE campaign run by UNC5142. EtherHiding embeds malicious JavaScript payloads inside smart contracts deployed on BNB Smart Chain and Ethereum, retrieved via read-only eth_call requests that create no visible transaction and incur no gas fees, giving attackers a decentralized, effectively unseizable hosting layer for C2 and payload delivery. UNC5342 lures software and cryptocurrency developers through fake recruiter personas on LinkedIn and job boards, impersonating shell companies (BlockNovas LLC, Angeloper Agency, SoftGlideLLC), moving the conversation to Telegram or Discord, and requesting a 'technical assessment' that requires the victim to clone and run a GitHub repository or npm package, or to fix a fake ClickFix video-call error by running attacker-supplied code. The resulting infection chain runs a JavaScript downloader (JADESNOW, evolved from the HexEval Loader lineage) that queries BNB Smart Chain/Ethereum smart contracts via eth_call, decodes Base64/XOR-encrypted payloads in memory, and drops the BEAVERTAIL JavaScript infostealer, which in turn deploys the INVISIBLEFERRET backdoor in both Python and JavaScript variants. BEAVERTAIL and INVISIBLEFERRET together harvest browser-stored credentials, session cookies, payment card data, and cryptocurrency wallet data (MetaMask, Phantom) plus password-manager vaults (1Password), compress the loot into ZIP archives, and exfiltrate it to attacker infrastructure and private Telegram chats. The JavaScript INVISIBLEFERRET variant additionally opens an interactive backdoor over TCP/3306 (masquerading as MySQL) supporting arbitrary command execution and file/directory exfiltration. UNC5342 has also folded this tooling into supply-chain operations, publishing malicious npm packages (including a June 2025 wave compromising React Native Aria/GlueStack-adjacent tooling and a subsequent wave of 35 typosquatted packages such as reactbootstraps and react-plaid-sdk) that pull JADESNOW/BEAVERTAIL at install time. On-chain, GTIG identified a primary BNB Smart Chain contract (0x8eac3198dd72f3e07108c4c7cff43108ad48a71c) updated 20+ times over four months at an average gas cost of $1.37 per update, owned by wallet 0x9bc1355344b54dedf3e44296916ed15653844509, and observed a parallel Ethereum-side 'dead drop resolver' technique (MITRE T1102.001) in which payload data is smuggled as transaction calldata sent to the null/burn address 0x000000000000000000000000000000000000dEaD, making the sender address itself irrelevant to retrieval. UNC5342 retrieves this data through centralized blockchain-explorer APIs (Binplorer, Blockchair, Blockcypher, Ethplorer) for redundancy, in contrast to UNC5142's direct RPC-node approach — a centralization dependency that gives defenders a practical intervention point despite the underlying blockchain's immutability. The campaign's dual objectives are cryptocurrency theft and espionage/persistent access against software and crypto-industry developers, and it remains active as of the October 2025 GTIG disclosure and subsequent 2026 reporting on continued front-company and npm-package waves.
MITRE ATT&CK techniques used in TL-2026-1511
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Execution
T1059.006 Python; T1059.007 JavaScript; T1204.002 Malicious File
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Command and Control
T1102 Web Service; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1571 Non-Standard Port
Initial Access
T1195.001 Compromise Software Dependencies and Development Tools; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
initial-access
T1195.002 Compromise Software Supply Chain
Persistence
T1505 Server Software Component
Credential Access
T1539 Steal Web Session Cookie; T1555.003 Credentials from Web Browsers
Resource Development
T1583.006 Web Services; T1585.001 Social Media Accounts
Reconnaissance
T1589 Gather Victim Identity Information
Impact
Affected products and versions in DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and
- npm — npm registry packages (typosquatted developer tooling)
Vulnerable versions: malicious packages including react-plaid-sdk, reactbootstraps, and 35+ typosquats of vite-plugin-*, react-*, *-logger, json*
Fixed in: N/A - malicious packages removed from registry by npm security team - Google Chrome / Enterprise browsers — Browser-stored credentials and extensions
Vulnerable versions: all versions absent enterprise download/URL restriction policy
Fixed in: N/A - mitigated via enterprise policy, not a software patch - MetaMask / Phantom — Cryptocurrency wallet browser extensions
Vulnerable versions: all versions - targeted for local credential/keystore theft, not a wallet software vulnerability
Remediation for DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and
Immediate actions
- Block outbound connections to known blockchain explorer APIs used for payload retrieval where not business-required (binplorer.com, blockchair.com, blockcypher.com, ethplorer.io)
- Block/alert on the identified malicious BNB Smart Chain contract (0x8eac3198dd72f3e07108c4c7cff43108ad48a71c) and owner wallet (0x9bc1355344b54dedf3e44296916ed15653844509)
- Block outbound TCP/3306 from developer endpoints to non-database infrastructure to disrupt INVISIBLEFERRET.JAVASCRIPT C2
- Remove/quarantine identified malicious npm packages and audit recent npm installs for typosquats of react-*, vite-plugin-*, *-logger, json* package families
- Advise developer staff on Contagious Interview social-engineering pattern: fake recruiters on LinkedIn moving contact to Telegram/Discord and requesting code execution as a 'technical assessment'
Workarounds
- Enterprise Chrome policy: DownloadRestrictions blocking dangerous file types (.exe, .msi, .bat, .dll)
- Enterprise Chrome policy: enforce automated silent background updates and train users that manual update prompts are never legitimate
- Enterprise Chrome policy: URLBlocklist for known malicious domains/blockchain explorer endpoints; enable Enhanced Safe Browsing
Longer-term hardening
- Deploy EDR with behavioral detection for Base64+XOR-decoded in-memory JavaScript/Python payload execution
- Enforce code-review sandboxing for any take-home technical assessment code from external recruiters (VM/container, no host credential access)
- Monitor npm registry package installs for known-malicious authors/publishers tied to Contagious Interview
- Integrate blockchain threat-intelligence feeds (malicious contract/wallet address lists) into network security controls
- Deploy browser policy restricting silent update prompts to reduce ClickFix-style fake update social engineering
Timeline of DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and
- EtherHiding technique first emerges as part of the financially motivated CLEARFAKE campaign attributed to UNC5142, embedding malicious JavaScript in BNB Smart Chain contracts.
- Guardio Labs publicly documents EtherHiding attacks using Binance Smart Chain contracts to deliver fake browser-update lures.
- BeaverTail malware resurfaces in malicious npm packages targeting developers, per The Hacker News reporting.
- UNC5342 begins incorporating EtherHiding into the ongoing Contagious Interview campaign, marking the first nation-state adoption of the technique.
- North Korean actors deploy BeaverTail malware via 11 additional malicious npm packages.
- Silent Push reports Contagious Interview creating three new front companies to distribute BeaverTail, InvisibleFerret, and OtterCookie.
- Software supply-chain attack compromises React Native Aria and GlueStack-adjacent npm packages; a wave of 35 new malicious/typosquatted npm packages (reactbootstraps, react-plaid-sdk, etc.) is identified across 24 publisher accounts.
- GTIG observes no further UNC5142 CLEARFAKE/EtherHiding activity after this date, suggesting a pause or tactical shift by that (separate, financially motivated) cluster.
- Google Cloud publishes 'New Group on the Block' detailing UNC5142's EtherHiding-based distribution of Atomic Stealer, Lumma, Rhadamanthys, and Vidar via ~14,000 compromised WordPress pages.
- Google Threat Intelligence Group publicly discloses UNC5342's adoption of EtherHiding to deliver JADESNOW and INVISIBLEFERRET via blockchain smart contracts, publishing IOCs including the BNB Smart Chain contract and owner wallet.
- Microsoft Security Blog publishes further detail on the Contagious Interview campaign delivering malware through fake developer job interviews, confirming continued activity.
Sources cited for DPRK's UNC5342 Adopts EtherHiding to Deliver JADESNOW and
- DPRK adopts EtherHiding in a new nation state first
- New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware
- Contagious Interview: Malware delivered through fake developer job interviews
- Another Wave: North Korean Contagious Interview Campaign Drops 35 New Malicious npm Packages
- North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages
- New wave of 'fake interviews' use 35 npm packages to spread malware
- Tenacious Pungsan: A DPRK threat actor linked to Contagious Interview
- BeaverTail Malware Resurfaces in Malicious npm Packages Targeting Developers
- Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies to Deliver a Trio of Malware: BeaverTail, InvisibleFerret, and OtterCookie
- North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages
- Hackers Abuse Blockchain Smart Contracts to Spread Malware via Infected WordPress Sites
Detection coverage for TL-2026-1511
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1511 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.