Join us

Inside the GitHub Infrastructure Powering North Korea’s Contagious Interview npm Attacks

The Socket Threat Research Team has been following North Korea’s Contagious Interview operation as it targets blockchain and Web3 developers through fake job interviews. The campaign has added at least 197 malicious npm packages and over 31,000 downloads since last report, showcasing the adaptability of North Korean threat actors to modern JavaScript and crypto development workflows. The recent wave of malicious npm packages exposes a delivery stack that leverages GitHub for hosting malware-serving code, Vercel for payload delivery, and a separate command and control (C2) server for data collection and tasking, highlighting how threat actors are exploiting npm to target developers.


Let's keep in touch!

Stay updated with my latest posts and news. I share insights, updates, and exclusive content.

Unsubscribe anytime. By subscribing, you share your email with @varbear and accept our Terms & Privacy.

Give a Pawfive to this post!


Only registered users can post comments. Please, login or signup.

Start writing about what excites you in tech — connect with developers, grow your voice, and get rewarded.

Join other developers and claim your FAUN.dev() account now!

Avatar

VarBear #SoftwareEngineering

FAUN.dev()

@varbear
SWE Weekly Newsletter, Varbear. Curated Programming news, tutorials, tools and more!
Developer Influence
1

Influence

1

Total Hits

60

Posts