ContagiousDrop is a malicious Node.js-based malware delivery system tracked by SentinelLABS and Validin under the Contagious Interview campaign cluster, which is associated with North Korean threat actors under the Lazarus umbrella. It has been observed embedded in fake recruitment and job assessment sites and used in ClickFix-style interview lures targeting individuals, primarily professionals in the cryptocurrency and blockchain sectors. The malware is typically implemented as Node.js applications such as app.js files and is designed to deliver payloads disguised as software updates or essential utilities. It identifies whether the victim is using Windows, macOS, or Linux and serves an OS-appropriate malware payload. Reported behavior includes notifying operators by email when victims engage with lure sites, download malicious files, or execute malicious commands, and logging victim information such as names, phone numbers, and IP addresses. Investigators reported exposed directories and logs on infrastructure including api.release-drivers[.]online, api.camdriverhelp[.]club, and api.drive-release[.]cloud, and identified email artifacts including marvel714jm[@]gmail.com and jimmr6587[@]gmail.com associated with related infrastructure. Exposed ContagiousDrop logs helped researchers identify more than 230 affected individuals between January and March 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure. Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.
We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure. Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
These notifications...provide the Contagious Interview threat actors with insights into victim engagement... initial and later engagements are captured in client_ips_start_test.json and client_ips_submit.json, including details such as full name, email address, IP address, phone number, and the date of interaction.
They distribute a tailored payload based on the victim’s operating system (Windows, macOS, or Linux), system architecture, and method of interaction with the server, such as the use of the curl command.
In addition to delivering malware, the ContagiousDrop applications feature an integrated email notification system... an email is triggered when an affected individual starts a fake skill assessment... These applications record victim information across multiple files and interaction points.
A targeted job seeker receives an invitation to participate in a job application process, directing them to a lure website where they are prompted to complete a skill assessment.
A targeted job seeker receives an invitation to participate in a job application process, directing them to a lure website where they are prompted to complete a skill assessment.
The Contagious Interview campaign, active since at least 2023, targets job seekers in the cryptocurrency and blockchain industries... These victims were mainly in marketing and finance roles within the cryptocurrency sector and were targeted with fake job offers from well-known companies like Archblock, Robinhood, and eToro.
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious Node.js application used to deploy additional malware disguised as updates or utilities, tailored to victim's OS and architecture.
A cross-platform malware delivery tool used in the Contagious Interview campaign. It masquerades as software updates, detects the victim operating system, and delivers the appropriate malicious payload.
A Node.js malware delivery application used on ClickFix distribution servers to deliver tailored payloads based on victim OS/architecture, log victim interactions, and send email notifications about engagement and malware download activity.
A malware delivery system embedded in fake recruitment sites, used to deliver malicious payloads and send email alerts when victims executed malicious commands while logging victim details such as names, phone numbers, and IP addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.