DPRK's Contagious Interview campaign is still running
2026-08-14 • Moonlock •
Moonlock Lab analyzed an active Contagious Interview chain targeting macOS users with a fake Git helper shell script that downloads a Node.js runner and an obfuscated OtterCookie payload. The payload steals browser passwords and Keychain data, scans files and clipboard contents, targets 40 cryptocurrency wallet extensions, and provides remote shell and file-access capabilities. Three workers beacon to 104.194.153.144, while the lure infrastructure uses githelper.store. Researchers said the payload's comments and inconsistent construction suggest increasing use of AI-generated code, although this remains an assessment rather than a proven development method.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f3c95dc199b343875bd2b66be43091c… | 2026-08-14 | 2026-08-14 |
| HASH | 4cd973b787d5a489a5281adfa0ab02e… | 2026-08-14 | 2026-08-14 |
| HASH | 9fe86f0b19fb4d6ac47100f72a9b7f0… | 2026-08-14 | 2026-08-14 |
| HASH | cc92280557b399ec9271af08c5b6f57… | 2026-08-14 | 2026-08-14 |
| HASH | a8d61b58e99a4bfd549aeb4eb9499cf… | 2026-08-14 | 2026-08-14 |
| IPv4 | 104.194.153.144 | 2026-08-14 | 2026-08-14 |
| DOMAIN | githelper.store | 2026-08-14 | 2026-08-14 |