Microsoft and Enki White Hat reported ongoing “Contagious Interview” activity in which threat actors impersonate recruiters and run realistic developer interview workflows to trick targets into executing malicious code. The campaign targets software developers (including at enterprise solution providers and media/communications firms) and has been active since at least December 2022, using lures such as coding assignments and repositories hosted on common platforms (e.g., GitHub, GitLab, Bitbucket). Recent intrusions show an adaptation to Visual Studio Code workflows: victims are prompted to trust the repository, and once trust is granted, VS Code can automatically execute attacker-supplied task configurations, turning a routine “open the project” step into an initial execution vector.
Technical analysis describes GitHub-hosted repositories containing a malicious .vscode/tasks.json where runOptions.runOn is set to folderOpen, causing hidden, whitespace-obfuscated commands to run when the folder is opened in VS Code. The tasks execute OS-specific downloaders that fetch and run follow-on scripts from C2 infrastructure; on Linux/macOS, a script is downloaded to $HOME/Documents/tokenlinux.npl, renamed to tokenlinux.sh, and executed, while Windows attempts to download to %USERPROFILE%/parse and rename to token.cmd (the Windows payload was unavailable during analysis due to an “Access permanently suspended.” response). The Linux/macOS chain includes a downloader assessed to be LLM-generated (noted for unusually detailed comments and emoji usage), which stages a local Node.js runtime, pulls additional files such as parser.js and package.json, and executes the obfuscated JavaScript downloader; observed payload sets include BeaverTail and InvisibleFerret, with OtterCookie also deployed in some paths depending on environment or attack stage.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Enki White Hat published analysis focused on the Contagious Interview campaign's abuse of Visual Studio Code distributed through GitHub. The post documented the same broader operation in Korean and English-language versions.
Microsoft Defender Experts published research describing the long-running Contagious Interview campaign and its tactics, malware, and targeting. The report also noted increasing use of modular cross-platform malware, obfuscation, and abuse of developer tooling.
Microsoft reported that the operation used multiple malware families, including the JavaScript beaconing agent OtterCookie as well as Invisible Ferret and FlexibleFerret. The tooling provided persistence, remote access, and theft of developer-held secrets such as API tokens, cloud credentials, signing keys, wallets, and source code.
During the campaign, threat actors lured victims into running malicious NPM packages or Visual Studio Code tasks from GitHub, GitLab, and Bitbucket repositories. The activity abused trust in technical interview exercises to gain execution on developer systems.
Microsoft said the Contagious Interview social-engineering operation has been active since at least December 2022. The campaign impersonates recruiters and targets software developers through fake job interview workflows.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
enki.co.kr
Open sourceenki.co.kr
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.