DPRK-linked operators expanded the Contagious Interview social-engineering campaign by posing as recruiters and sending developers malicious GitHub or GitLab repositories that execute malware when opened in Visual Studio Code. Researchers said the attack does not rely on a software vulnerability; instead, it abuses trusted developer workflows, including .vscode/tasks.json, package.json, and Next.js configuration files, to trigger background execution after a victim opens a project and trusts the author. In observed cases, npm start or a VS Code task launched a staged JavaScript payload, including code hidden in files such as scripts/jquery.min.js, which then contacted attacker infrastructure hosted on Vercel and related domains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
20 events from the most recent confirmed update back to the earliest known activity.
A Microsoft Security Blog reference indicates publication of a report on a C2 developer-targeting campaign. No further factual content was supplied in the reference block to extract additional distinct events.
Ransom-ISAC reported that the 66.235.168.136 server was first observed with this C2 configuration on 24 January 2026. It matched the same Node.js/Express characteristics and /api/errorMessage pattern seen across related infrastructure.
Ransom-ISAC reported that the 87.236.177.9 server was first observed with this C2 configuration on 23 January 2026. The server used the /api/errorMessage endpoint later associated with BeaverTail overlap and Contagious Interview tradecraft.
The January 2026 campaign used a GitHub repository whose .vscode/tasks.json auto-ran npm start when opened in VS Code, while a weaponized next.config.js evaled a trojanized scripts/jquery.min.js stager. The stager fetched remote JavaScript from api-web3-auth.vercel.app and executed it without exploiting a software vulnerability.
Security researcher François-Julien Alcaraz was targeted in January 2026 by a fake recruitment campaign aimed at developers. The lure used LinkedIn recruiter personas, a Google Meet interview, and a malicious GitHub coding challenge.
Jamf Threat Labs reported that in December it identified additional abuse of Visual Studio Code tasks.json files, including obfuscated JavaScript executed when a victim opened a malicious repository. This reflected an evolution in the DPRK-attributed Contagious Interview campaign's initial execution method.
Ransom-ISAC stated that C2 IPs 66.235.168.136 and 87.236.177.9 had been active at least since mid-September of the previous year. The infrastructure later supported the VS Code-to-RAT campaign's /api/errorMessage beaconing pattern.
Ransom-ISAC and Crystal Intelligence investigated a September 2025 cryptocurrency and data theft attempt that originated from a private weaponized GitHub repository. The campaign evolved from an apparent phishing lure into a multi-layered attack using blockchain-based command-and-control and cross-platform malware.
Temporal analysis in the Ransom-ISAC investigation showed most pointer-address activity began in early June 2025 during weekdays. This marked the start of sustained blockchain-based command-and-control preparation.
SecurityScorecard reported that it identified an ongoing Lazarus Group supply-chain campaign dubbed Operation 99 on January 9. The operation targeted software developers through fake recruiter outreach and malicious GitLab repositories, deploying modular malware to steal source code, secrets, and cryptocurrency wallet material across Windows, macOS, and Linux.
Ransom-ISAC said the BOT250205 token contract had only 23 transactions since early 2025 and appeared to function mainly as an additional field for transaction text. The contract was tied to the campaign's cross-chain pointer infrastructure.
A BSC wallet used in the campaign, 0xab57bf80d77bf250331f9e1a523b2c11485a1a64, received more than 25,000 USDT between October 2024 and April 2025. Forward tracing from this wallet later showed bridging activity with exposure to addresses linked to North Korean thefts.
A public IoC report documented a social-engineering campaign using LinkedIn job or project lures and convincing GitHub repositories with hidden malicious code targeting development companies. The reporter submitted the activity to the Microsoft Security Response Center on 2024-09-27, establishing an earlier dated disclosure of this developer-focused intrusion method.
Ransom-ISAC reported that several infrastructure addresses tied to the blockchain-enabled campaign had been dormant since as far back as 2021 before being operationalized. This marks the earliest explicit temporal anchor in the references for the broader activity.
Ransom-ISAC published SHA-256 hashes for malicious files and a YARA rule named Actor_APT_DPRK_MAL_SCRIPT_JS_Dropper_Unknown_Strings_Mar26 to detect JavaScript droppers used in the campaign. The report also listed related staging domains and infrastructure characteristics.
Ransom-ISAC assessed the VS Code-to-RAT activity as linked to DPRK-affiliated operators and associated it with the Contagious Interview campaign, noting overlap with BeaverTail-related reporting. The article also identified additional likely related C2 IPs and staging domains through infrastructure pivoting.
Jamf Threat Labs reported an identified malicious repository to GitHub, and the repository was removed. Before takedown, Jamf observed the payload URL referenced in the repository change multiple times, including after a Vercel takedown.
Jamf Threat Labs observed additional JavaScript instructions executed roughly eight minutes after initial infection. The follow-on payload beaconed to the same C2 infrastructure, launched detached child Node processes, and included cleanup logic to stop managed processes on command.
Observed malware samples fingerprinted the host, beaconed every five seconds to C2 infrastructure, and could execute arbitrary JavaScript returned by the server. Jamf and Ransom-ISAC both described the same core behavior, including use of 87.236.177.9:3000/api/errorMessage and dynamic code execution.
A separate victim account described an attempted compromise through a fake job interview. The reference provides only the publication date metadata and no explicit event date in the supplied content, so the event date cannot be set.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
ransom-isac.org
Open sourceransom-isac.org
Open sourceblog.daviddodda.com
Open sourcegithub.com
Open sourcesecurityscorecard.com
Open sourcejamf.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.