The record
Written from the 1 report below. Nothing here is unsourced.
- North Korean hackers linked to the Contagious Interview campaign are targeting software developers with fake job postings and coding tests delivered through channels like Slack.
- The malicious code is hidden inside SVG image files that look like normal country flags, and running the 'assignment' installs a four-stage payload aligned with OtterCookie malware.
- The malware steals browser credentials, cryptocurrency wallets, files, and clipboard data, and includes a remote access trojan.
- The campaign matters because compromising even one developer could enable broader supply chain attacks against downstream organizations.
What to watch next
- Whether more repositories published by unwitting victims appear on GitHub
- Further evolution of OtterCookie's modules, including its targeting of AI coding tool extensions
- Continued use of public platforms like Slack, Discord, and LinkedIn for impersonation lures
Coverage1
1 report
English national1
All filed from India
Named United States · Netherlands · North Korea · OtterCookie · Slack · Contagious Interview · Daniel Stepanic · DPRK · Elastic Security Labs · Microsoft · REF9403
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
