North Korea-linked threat actors tied to the long-running Contagious Interview operation have been observed using malicious Microsoft Visual Studio Code (VS Code) projects as part of fake job-assessment lures, instructing targets to clone repositories from GitHub/GitLab/Bitbucket and open them in VS Code. The technique abuses VS Code tasks.json configuration—specifically "runOn": "folderOpen"—to trigger execution when a folder is opened, pulling staged payloads from attacker-controlled infrastructure (including Vercel-hosted domains) and ultimately deploying backdoors such as BeaverTail and InvisibleFerret that enable remote code execution and follow-on control. Recent iterations reportedly add multi-stage droppers embedded in task configuration content and disguised as benign files (e.g., spell-check dictionaries) to improve resilience if network retrieval fails, and include command-and-control behavior that can execute attacker-supplied JavaScript from a remote server (e.g., ip-regions-check.vercel[.]app).
Separate reporting on North Korean APT trends indicates continued reliance on fraudulent IT employment schemes and recruitment-platform abuse to gain access to Western organizations, including long-term social engineering and persistent remote access via legitimate tools (e.g., AnyDesk, Google Remote Desktop) and VPN/location obfuscation. This broader pattern aligns with the same overarching tradecraft used in developer-targeted “interview” lures: leveraging hiring workflows and developer tooling to establish initial access and persistence while reducing suspicion, particularly in environments with remote-work infrastructure and developer workstations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
Researchers reported an ongoing North Korea-linked PolinRider operation tied to Contagious Interview that distributed 108 malicious packages and browser extensions across npm, Packagist, Go, and the Chrome Web Store, producing 162 malicious release artifacts. The activity involved compromised maintainer accounts, tampered legitimate repositories, and malware delivery leading to DEV#POPPER RAT and OmniStealer.
A first-person incident report described suspected DPRK-linked malware concealed in a tailwind.config.js file in a Node.js project, with the payload heavily obfuscated and hidden after extensive whitespace. The discovery prompted incident response actions including killing production processes, rotating credentials, and investigating an unauthorized Git commit under the author's name.
Recorded Future's Insikt Group published findings tying the PurpleBravo cluster to 3,136 likely target IPs, 20 potential victim organizations, LinkedIn recruiter personas, and separate C2 infrastructure for BeaverTail and GolangGhost. The report also noted operational overlaps with the North Korean IT-worker fraud campaign known as Wagemole/PurpleDelta.
In January 2026, Jamf Threat Labs reported that the Contagious Interview campaign had evolved to abuse VS Code repository trust and task configuration files to trigger malicious commands, including a previously unseen JavaScript backdoor on macOS. Jamf also identified a new Node.js ecosystem infection method in which malicious code executes during a standard npm install.
AhnLab ASEC published a trend report consolidating North Korea-aligned activity observed in December 2025, including Famous Chollima fake IT worker operations and Lazarus malware delivery via a WinRAR exploit. The report highlighted a broader shift toward combining social engineering, remote-work abuse, and software exploitation.
Jamf Threat Labs first noted in December 2025 that DPRK-linked attackers were abusing Visual Studio Code tasks.json files with the runOn: folderOpen setting to execute code when a victim opened a cloned repository. The technique delivered malware including BeaverTail and InvisibleFerret through job-assessment lures.
Lazarus Group distributed a malicious archive named Pharos.rar that exploited WinRAR path traversal vulnerability CVE-2025-8088 to place a BAT file in the Startup folder. The infection chain deployed a multi-stage Python loader leading to the Blank Grabber infostealer, using Dropbox, Pastebin, and Telegram in the process.
Microsoft Incident Response (DART) linked a Famous Chollima case using PiKVM hardware-based remote control to the Jasper Sleet threat cluster. The technique was used to bypass endpoint detection and response controls while maintaining remote access.
During 2025, North Korea-aligned Famous Chollima used fake IT worker schemes, identity theft, GitHub pull-request outreach, VPNs, and remote desktop tools such as AnyDesk and Google Remote Desktop to obtain and maintain covert access to corporate environments. The activity also involved soliciting victims' personal identity information.
Recorded Future assessed the North Korea-linked PurpleBravo/Contagious Interview cluster targeted 3,136 IP addresses and 20 potential victim organizations across multiple sectors and regions. The activity primarily affected targets in South Asia and North America between August 2024 and September 2025.
North Korea-linked operators behind the Contagious Interview campaign were active by late 2023, using fake job and interview lures to target developers and IT workers, especially in blockchain and cryptocurrency. The campaign supported espionage, credential theft, initial access, and financially motivated activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourceinfosecwriteups.com
Open sourcebsky.app
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.