⤷ Title: North Korea’s “Contagious Interview” Floods npm with 200 New Packages, Using Fake Crypto Jobs to Deploy OtterCookie Spyware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:13:02 +0000
════════════════════════
⌗ Tags: #Cyber Security #BeaverTail #Contagious Interview #Job Scam #North Korea APT #NPM Supply Chain #OtterCookie #Typosquatting #Web3 Theft
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 01 Dec 2025 00:13:02 +0000
════════════════════════
⌗ Tags: #Cyber Security #BeaverTail #Contagious Interview #Job Scam #North Korea APT #NPM Supply Chain #OtterCookie #Typosquatting #Web3 Theft
Daily CyberSecurity
North Korea's "Contagious Interview" Floods npm with 200 New Packages, Using Fake Crypto Jobs to Deploy OtterCookie Spyware
North Korean APTs added 197 malicious npm packages to the "Contagious Interview" campaign. The operation uses fake crypto job assignments to deploy the OtterCookie/BeaverTail hybrid to steal credentials cross-platform.
⤷ Title: N. Korea’s Contagious Interview Campaign Targets Job Seekers with 197 Malicious npm Packages
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:30:58 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Contagious Interview #DPRK #GolangGhost #Job Seeker Scam #North Korea APT #npm #OtterCookie #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 04:30:58 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Contagious Interview #DPRK #GolangGhost #Job Seeker Scam #North Korea APT #npm #OtterCookie #supply chain attack
Penetration Testing Tools
N. Korea's Contagious Interview Campaign Targets Job Seekers with 197 Malicious npm Packages
North Korea’s Contagious Interview malware campaign continues to escalate its pressure on the JavaScript-development ecosystem. Threat actors affiliated
⤷ Title: NK Hackers Push 200 Malicious npm Packages with OtterCookie Malware
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 16:34:09 +0000
════════════════════════
⌗ Tags: #Malware #Security #BeaverTail #Contagious Interview #Cyber Attack #Cybersecurity #Lazarus #North Korea #NPM #OtterCookie
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 02 Dec 2025 16:34:09 +0000
════════════════════════
⌗ Tags: #Malware #Security #BeaverTail #Contagious Interview #Cyber Attack #Cybersecurity #Lazarus #North Korea #NPM #OtterCookie
Hackread
NK Hackers Push 200 Malicious npm Packages with OtterCookie Malware
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: “Contagious Interview” Goes macOS: North Korean Hackers Deploy Stealthy “DriverFixer” Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:06:47 +0000
════════════════════════
⌗ Tags: #Malware #Apple Security #Contagious Interview #credential stealer #cyber_espionage #DriverFixer0428 #Dropbox C2 #macOS Malware #North Korea #Sandbox Evasion #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 25 Dec 2025 00:06:47 +0000
════════════════════════
⌗ Tags: #Malware #Apple Security #Contagious Interview #credential stealer #cyber_espionage #DriverFixer0428 #Dropbox C2 #macOS Malware #North Korea #Sandbox Evasion #social engineering
Daily CyberSecurity
“Contagious Interview” Goes macOS: North Korean Hackers Deploy Stealthy “DriverFixer” Stealer
A notorious North Korean cyber-espionage campaign known for targeting job seekers has expanded its arsenal with a sophisticated new tool aimed specifically at macOS users. A new analysis by securi…
⤷ Title: Fake Jobs, Real Theft: “Contagious Interview” Malware Drains Crypto Wallets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 00:36:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BeaverTail #Contagious Interview #Cryptocurrency Theft #Invisible Ferret #malware #MetaMask Security #North Korean hackers #Python Malware #social engineering #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 18 Feb 2026 00:36:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BeaverTail #Contagious Interview #Cryptocurrency Theft #Invisible Ferret #malware #MetaMask Security #North Korean hackers #Python Malware #social engineering #Web3 security
Daily CyberSecurity
Fake Jobs, Real Theft: "Contagious Interview" Malware Drains Crypto Wallets
North Korean hackers target IT pros with "Contagious Interview" malware. Fake job offers install trojanized MetaMask extensions to steal crypto.
⤷ Title: The Invisible Switch: North Korean Hackers Use “Contagious Interviews” to Trojanize Your MetaMask
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:59:27 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail #Chrome Security #Contagious Interview #Crypto Theft #Developer Security #InvisibleFerret #malware #MetaMask #North Korea #OtterCookie #Secure Preferences #Tech News 2026
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 20 Feb 2026 04:59:27 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail #Chrome Security #Contagious Interview #Crypto Theft #Developer Security #InvisibleFerret #malware #MetaMask #North Korea #OtterCookie #Secure Preferences #Tech News 2026
Penetration Testing Tools
The Invisible Switch: North Korean Hackers Use "Contagious Interviews" to Trojanize Your MetaMask
North Korean cyber-adversaries are endeavoring to surreptitiously supplant the MetaMask cryptocurrency wallet extension directly upon a victim’s workstation—an
⤷ Title: Hired to Hack: North Korean Fake IT Workers Hijack Exec Identities in ‘Contagious Interview’ Scams
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #Cyber Security #Fake IT Workers #GitLab Threat Intelligence #identity theft #infosec #Insider Threat #North Korean IT workers #Remote Work Security #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:18:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #Cyber Security #Fake IT Workers #GitLab Threat Intelligence #identity theft #infosec #Insider Threat #North Korean IT workers #Remote Work Security #social engineering
Daily CyberSecurity
Hired to Hack: North Korean Fake IT Workers Hijack Exec Identities in 'Contagious Interview' Scams
GitLab reveals how North Korean fake IT workers use 'Contagious Interview' scams to bypass hiring, steal data, and hijack executive digital identities.
⤷ Title: North Korean “StegaBin” Campaign Targets Developers with Steganographic Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 02:53:18 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #infosec #Lazarus Group #npm Security #pastebin #Socket #StegaBin #steganography #supply chain attack #truffleHog
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 03 Mar 2026 02:53:18 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #infosec #Lazarus Group #npm Security #pastebin #Socket #StegaBin #steganography #supply chain attack #truffleHog
Daily CyberSecurity
North Korean "StegaBin" Campaign Targets Developers with Steganographic Malware
Socket uncovers "StegaBin," a North Korean malware campaign hiding C2 URLs in Pastebin essays to steal developer secrets via 26 typosquatted npm packages.
⤷ Title: The ‘Contagious Interview’ Trap: How a Web3 CEO Unmasked North Korean Stealth Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:07:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #infosec #Kill Switch #LinkedIn Phishing #Malware Analysis #North Korean malware #social engineering #threat intelligence #Web3 security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 00:07:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #infosec #Kill Switch #LinkedIn Phishing #Malware Analysis #North Korean malware #social engineering #threat intelligence #Web3 security
Daily CyberSecurity
The 'Contagious Interview' Trap: How a Web3 CEO Unmasked North Korean Stealth Malware
A fake LinkedIn recruiter and a poisoned GitHub repo: See how a CEO uncovered the North Korean "Contagious Interview" malware targeting Web3 developers.
⤷ Title: The Fake Job Trap: Microsoft Exposes the ‘Contagious Interview’ Campaign Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 03:19:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #developer security #DevSecOps #infosec #Invisible Ferret #Microsoft Defender Experts #OtterCookie #phishing #social engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 03:19:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #cybersecurity #developer security #DevSecOps #infosec #Invisible Ferret #Microsoft Defender Experts #OtterCookie #phishing #social engineering
Daily CyberSecurity
The Fake Job Trap: Microsoft Exposes the 'Contagious Interview' Campaign Targeting Developers
Microsoft exposes the "Contagious Interview" campaign. Fake recruiters trick developers into installing Invisible Ferret malware during coding tests.
⤷ Title: The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:52:30 +0000
════════════════════════
⌗ Tags: #Malware #Anthropic #Contagious Interview #Cursor AI #Cybersecurity 2026 #Developer Security #gemini_ai_checker #North Korea #NPM Malware #OtterCookie #supply chain attack #Windsurf
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 07 Apr 2026 07:52:30 +0000
════════════════════════
⌗ Tags: #Malware #Anthropic #Contagious Interview #Cursor AI #Cybersecurity 2026 #Developer Security #gemini_ai_checker #North Korea #NPM Malware #OtterCookie #supply chain attack #Windsurf
Penetration Testing Tools
The Gemini Trap: How a Fake AI Token Checker Stealthily Hijacks Developer Workstations
An ostensibly innocuous package for validating Google Gemini tokens manifested within the npm repository, yet beneath its rudimentary
⤷ Title: The 1,700-Package Blitz: North Korea’s “Contagious Interview” Infiltrates Every Major Dev Registry
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 08 Apr 2026 02:12:15 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #cybersecurity #go #infosec #Malicious packages #malware loader #North Korea #npm #php #PyPI #Rust #Socket #supply chain attack
Daily CyberSecurity
The 1,700-Package Blitz: North Korea’s "Contagious Interview" Infiltrates Every Major Dev Registry
North Korea’s "Contagious Interview" campaign expands to 1,700+ malicious packages across npm, PyPI, and more. Learn how to protect your dev environment.
⤷ Title: North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 02:00:41 +0000
════════════════════════
⌗ Tags: #Malware #AI Tools #API Key Theft #Claude Code #Contagious Interview #Cursor AI #Cyberespionage #developer security #infosec #North Korea #npm malware #OtterCookie #WindSurf
Daily CyberSecurity
North Korean Hackers Pivot to AI: New npm Malware Targets Cursor, Claude, and Gemini Tokens
North Korean hackers are now targeting AI tools like Cursor and Claude. The OtterCookie malware steals API keys and conversation logs. Is your dev environment safe?
⤷ Title: PolinRider Supply Chain Attack Spans npm, Go, Chrome
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 08:38:34 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #Go Modules Security #North Korea Hackers #NPM Malware #PolinRider #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 08:38:34 +0000
════════════════════════
⌗ Tags: #Malware #Contagious Interview #Famous Chollima #Go Modules Security #North Korea Hackers #NPM Malware #PolinRider #supply chain attack
Information Security News
PolinRider Supply Chain Attack Spans npm, Go, Chrome
PolinRider is no longer a story about a handful of malicious npm packages. Researchers at Socket uncovered 162 malicious release artifacts spread across 108 packages and browser extensions. The ca…
⤷ Title: North Korea-Linked PolinRider Supply Chain Attack Expands Across Open Source
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 07:53:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #DEV#POPPER #Famous Chollima #North Korean hackers #npm #Packagist #PolinRider #Socket #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 07:53:40 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #DEV#POPPER #Famous Chollima #North Korean hackers #npm #Packagist #PolinRider #Socket #supply chain attack
Daily CyberSecurity
North Korea-Linked PolinRider Supply Chain Attack Expands Across Open Source
At a Glance Actor / group Suspected North Korean actors in the Contagious Interview / Famous Chollima cluster (Socket assessment) Activity type Open-source supply chain campaign; hidden JavaScript…
⤷ Title: North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 07:15:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #developer targeting #DPRK #Elastic Security Labs #Infostealer #North Korea #OtterCookie #SVG steganography
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 07:15:12 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Contagious Interview #developer targeting #DPRK #Elastic Security Labs #Infostealer #North Korea #OtterCookie #SVG steganography
Daily CyberSecurity
North Korean Contagious Interview Campaign Hides Malware in Fake Coding Tests
At a glance Actor / group DPRK-aligned group behind the Contagious Interview campaign (Elastic tracks it as REF9403) Activity type Social-engineering job lures delivering trojanized coding project…
⤷ Title: macOS ClickFix EtherHiding: DPRK Backdoor Hides C2 in Ethereum Smart Contracts
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:11:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Contagious Interview #Crypto_Stealer #DPRK #EtherHiding #macOS Malware #Node.js Backdoor #UNC5342
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 13:11:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #Contagious Interview #Crypto_Stealer #DPRK #EtherHiding #macOS Malware #Node.js Backdoor #UNC5342
Information Security News
macOS ClickFix EtherHiding: DPRK Backdoor Hides C2 in Ethereum Smart Contracts
A routine internet search can culminate in a full macOS compromise – one in which a counterfeit system update prompt manipulates the user into executing a malicious command themselves, and t…