Contagious Interview is a North Korea-linked malware campaign and intrusion cluster, also tracked as UNC5342, centered on social engineering of developers and job seekers through fraudulent interview and coding-assessment lures. The operation is widely associated with Lazarus Group tradecraft and has evolved across multiple delivery chains, including fake recruiter outreach, malicious GitHub repositories, poisoned open-source packages, and ClickFix-style fake update pages. Victims are commonly induced to clone or execute code locally, disable containerized environments, or paste attacker-supplied commands into a terminal, enabling staged compromise early in the developer workflow.
The campaign has used multi-stage loaders embedded in developer artifacts such as VS Code tasks, package installation logic, fake font resources, and malicious Git hooks including pre-commit and post-checkout hooks. These loaders fingerprint the victim environment, suppress visible errors, and retrieve platform-specific follow-on payloads for macOS, Linux, and Windows. Contagious Interview infrastructure has also been observed gating payload delivery based on IP geolocation, request metadata, runtime conditions, and other victim-environment details, reflecting deliberate execution control and anti-analysis behavior.
Observed payloads include backdoors and information stealers used for credential theft and cryptocurrency theft. Reported capabilities include arbitrary code execution, persistence on macOS through LaunchAgent mechanisms, periodic command-and-control polling, browser data theft, theft of SSH keys and cloud or developer credentials, and targeting of numerous cryptocurrency wallets. The campaign has also deployed malicious browser extensions to tamper with or drain cryptocurrency wallets, including MetaMask-related activity. Some variants have used blockchain-backed dead-drop or command-and-control discovery mechanisms such as EtherHiding to make infrastructure more resilient.
Contagious Interview has expanded beyond classic interview lures into broader software supply-chain abuse. Related activity has included large-scale malicious package distribution across ecosystems such as npm, PyPI, Go, Rust, and PHP, as well as GitHub repository compromise and JavaScript injection campaigns linked to adjacent Lazarus operations such as TasksJacker and PolinRider. Across these variants, the strategic objective remains consistent: compromise developers, steal credentials and wallet material, and leverage trusted development environments and accounts for further intrusion and propagation. The campaign has been especially associated with crypto, DeFi, and web3 themes, but observed targeting has also extended to general developers and macOS users reached through malvertising and search-engine abuse.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The OpenSourceMalware team discovered a fresh twist in the DPRK Lazarus Group Contagious Interview / TaskJacker playbook. Operators are hiding their stage-2 loader inside Git hooks... It's the same Contagious Interview social engineering — fake recruiter, "coding assessment" repo, multi-stage loader pulling InvisibleFerret-style implants for crypto wallet and credential theft...
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DPRK-linked malware operation targeting macOS users via malvertising, fake full-screen macOS update pages, and ClickFix-style clipboard poisoning to trick victims into executing a Terminal command that downloads a Node.js backdoor and follow-on payloads.
A Lazarus-associated campaign described as the broader or parallel operation from which PolinRider continues or derives.
A North Korea-linked cross-ecosystem campaign spanning npm, PyPI, Go, Rust, and Packagist that delivered staged RAT payloads through software package ecosystems.
Referenced as the named operation/campaign discussed in the post title; no technical malware functionality is described in the provided content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.