North Korea-linked operators tracked as HexagonalRodent, Contagious Interview, and overlaps of Lazarus/Famous Chollima used fake recruiter outreach on LinkedIn and sham company infrastructure to lure software and Web3 developers into opening malicious coding assessments. Researchers said the campaign delivered malware including BeaverTail, InvisibleFerret, and OtterCookie through backdoored GitHub repositories, rogue npm content, malicious VS Code tasks.json execution, and weaponized Git hooks such as pre-commit and post-checkout. The malware targeted Windows, macOS, and Linux systems, stealing browser credentials, keychains, wallet data, seed phrases, and developer secrets while maintaining persistence and remote access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-03, reporting described a North Korea-linked campaign dubbed PolinRider that hid JavaScript loaders in open source repositories, Go modules, Packagist packages, and a Chrome extension, with execution often triggered through malicious VS Code task files. Researchers said the activity was tied to the broader Contagious Interview/Famous Chollima ecosystem and involved 162 malicious release artifacts across 108 packages and extensions, using blockchain RPC services to fetch encrypted second-stage payloads including DEV#POPPER and OmniStealer.
On 2026-06-16, Python developer Roman Imankulov reported a suspected social-engineering supply-chain attack in which a fake recruiter sent him a malicious Node.js repository during a hiring process. He identified a backdoor in app/test/index.js and an npm prepare post-install hook that would execute attacker-controlled payloads during npm install, avoiding compromise by analyzing the code in an isolated environment.
On 2026-06-11, a Kmsec article highlighted North Korea-linked job advertisement activity using Google Docs, associated in the reference with the Famous Chollima cluster. The reporting points to a new lure or delivery mechanism within the broader recruiter-themed campaign targeting developers.
On 2026-05-28, TrendAI Research reported that the DPRK-aligned Void Dokkaebi/Famous Chollima cluster had evolved InvisibleFerret from readable Python into Cython-compiled native binaries delivered as .pyd and .so files. The report said the campaign still used fake job interview lures and BeaverTail staging while adding techniques to hinder detection and analysis.
On 2026-05-27, a developer posted that they were likely targeted by North Korea in a sophisticated malware campaign aimed at developers, explicitly referencing Contagious Interview and VS Code themes.
On 2026-05-26, Elastic Security Labs observed a fake recruiter in its community Slack workspace lure developers into direct messages and deliver trojanized coding challenges tied to the DPRK-linked Contagious Interview campaign. The malicious repositories concealed JavaScript in SVG image files via steganography and launched a four-stage OTTERCOOKIE-aligned payload chain that stole browser credentials, crypto-wallet data, files, and clipboard contents.
On 2026-05-16, Red Asgard published technical analysis separating OtterCookie from BeaverTail and InvisibleFerret, describing it as a JavaScript/Node.js RAT using Socket.IO for persistent command-and-control and continuous collection from active developer workstations. The analysis also linked delivery to malicious npm packages and Vercel-hosted staging infrastructure.
On 2026-05-12, researchers reported that Lazarus-linked actors were using malicious Git hooks in fake coding-test repositories so that commits or branch switches would trigger platform-specific malware delivery. The activity was tied to the Contagious Interview campaign and associated with BeaverTail and InvisibleFerret.
On 2026-05-08, a GitHub Gist analysis documented NitroGem, a malicious GitHub repository disguised as a React/Web3 dApp used in fake job-interview workflows to target developers. The trojan executed during npm install via a prepare script, fetched a public Google Doc to derive its C2 URL, exfiltrated the victim's process.env, and ran attacker-supplied JavaScript for remote code execution.
On 2026-04-23, reporting detailed how Serbia-based developer Boris Vujičić was lured through LinkedIn and realistic interviews into running a malicious coding test on macOS, after which attackers exfiltrated Chrome passwords, Keychain data, and MetaMask wallet information within 56 seconds. Incident responders at zeroShadow assessed that North Korean government-linked actors were likely responsible.
In early 2026, the HexagonalRodent subgroup expanded beyond fake coding tests into at least one supply-chain compromise by tampering with the fast-draft VSX extension to distribute OtterCookie.
During the first three months of 2026, Expel assessed that the DPRK-linked HexagonalRodent operation exfiltrated 26,584 cryptocurrency wallets from 2,726 infected developer systems, with exposed wallets tied to up to $12 million in crypto assets. The campaign targeted Web3 developers with fake job offers and backdoored coding assessments using BeaverTail, OtterCookie, and InvisibleFerret.
On 2026-04-22, Expel published findings on HexagonalRodent, describing a DPRK-linked operation targeting Web3 developers with fake job offers, BeaverTail, OtterCookie, and InvisibleFerret, and extensive use of generative AI for malware development, phishing infrastructure, and evasion testing. Expel also said it uncovered internal panels and workflows indicating a multi-team operation.
On 2026-01-27, researchers described a North Korea-linked 'Fake Font' campaign in which fake recruiters sent developers to GitHub projects containing malicious VS Code tasks and JavaScript disguised as font files, leading to InvisibleFerret infections across Windows, macOS, and Linux.
By early 2025, reporting identified OtterCookie as a new malware family used in the Contagious Interview operation alongside BeaverTail and InvisibleFerret, expanding the campaign's tooling against developer targets.
On 2023-11-22, Palo Alto Networks Unit 42 reported that North Korean threat actors were running the Contagious Interview campaign, impersonating recruiters to infect software developers with BeaverTail and InvisibleFerret malware via fake job interview lures and rogue GitHub/npm content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
34 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourceelastic.co
Open sourcearchive.ph
Open sourcearchive.ph
Open sourcethehackernews.com
Open sourcedocs.npmjs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.