Researchers reported a newly observed malware campaign that used a fake job interview coding challenge to infect developers with platform-specific stagers on Windows, macOS, and Unix-like systems, a lure pattern they associated with DPRK-linked activity. The infection chain created a hidden fake Visual Studio Code directory, downloaded bootstrap scripts, gathered host information, and then fetched a final payload named ghost.js on Unix/macOS or ghost.npl on Windows; a related social post highlighted the campaign’s phishing and VS Code themes.
The malware collected system details including hostname, platform, IP address, and MAC address, then registered victims with a command-and-control server using a Base64-decoded endpoint and key. Researchers said the payload used familiar obfuscation techniques and had no VirusTotal detections at the time of analysis, and they published infrastructure and hashes tied to the operation, including C2 141.94.148.39:1224 and a related Vercel-hosted domain that was reportedly taken down; they also said weaknesses in the C2 design allowed repeated spoofed victim registrations that could disrupt the server.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
A Bluesky account, lazarusholic, shared a link to Bitso's "North Korea’s Crypt: Hunting Ghosts" article with the hashtags #Phishing and #VSCode. The post did not add substantive new incident details beyond amplifying the report.
Bitso published the article "North Korea’s Crypt: Hunting Ghosts," detailing the fake interview lure, malware chain, infrastructure, and file hashes tied to the campaign. At the time of analysis, the researchers said the final payloads had zero VirusTotal detections.
The researchers said they identified a flaw that let them repeatedly spoof victim registration requests to the command-and-control server. They claimed they could make the server believe a victim named "QuetzalTeam" had been registered multiple times per second, disrupting the infrastructure.
The malicious domain ip-checking-psi[.]vercel[.]app, used in the fake coding challenge, was reportedly taken down quickly. This removed one piece of infrastructure tied to the campaign.
The authors associated the fake interview lure and malware tradecraft with DPRK-linked malware activity based on familiar patterns and obfuscation techniques they said they had seen repeatedly over the last three years. They also documented the malware's host-registration behavior and C2 infrastructure at 141.94.148.39:1224.
Researchers described a newly observed malware infection delivered through a fake job interview coding challenge sent to a Quetzal Team developer named Alex. The lure used a Vercel-hosted domain and deployed platform-specific stagers that ultimately fetched the final payload ghost.js or ghost.npl.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.