Contagious Interview is the name Palo Alto Networks' Unit 42 gave in November 2023 to an ongoing campaign, tracked internally as CL-STA-0240, that Unit 42 attributes with moderate confidence to a North Korea state-sponsored threat actor. Unit 42 found the activity, dating to at least December 2022, poses as employers offering software development jobs, luring victims through fake interviews into installing malicious npm packages hosted on GitHub; this delivers malware Unit 42 named BeaverTail, a cross-platform information stealer and loader, followed by a Python backdoor named InvisibleFerret, with an objective of cryptocurrency theft and establishing footholds for further attacks. Unit 42 has continued to track the campaign's evolution, including a cross-platform BeaverTail variant compiled with the Qt framework in mid-2024. Other researchers, including Datadog, have linked additional malicious npm packages and distinct threat-actor clusters, such as one Datadog separately named Tenacious Pungsan, to the same Contagious Interview activity targeting software and blockchain developers.
Search
Actors (10 of 12)
MITRE ATT&CK profiles Moonstone Sleet (G1036) as a North Korea-linked threat actor conducting both financially motivated attacks and espionage operations that previously overlapped significantly with the Lazarus Group before differentiating its tradecraft from 2023 onward. The group is noted for creating fake companies and personas, including social media and email accounts, to engage victim organizations and gather information ahead of intrusions, and for developing unique malware such as a payload delivered through a fully functioning game. Moonstone Sleet has distributed a trojanized version of the PuTTY utility as a software supply chain compromise, developed malicious npm packages, and delivered payloads through spearphishing attachments and social media services. Observed intermediate loaders such as YouieLoader and SplitLoader create malicious services and perform system, network, and browser information discovery, while the group has also dumped credentials from LSASS memory, used scheduled tasks for persistence and execution, and deployed ransomware for impact, reflecting a mixed espionage and financially motivated operational profile.
GitHub disclosed a low-volume social engineering campaign, publicly attributed with high confidence to a group it identified as Jade Sleet per Microsoft Threat Intelligence naming and TraderTraitor per CISA, that targeted personal accounts of technology-industry employees, primarily those connected to blockchain, cryptocurrency, and online gambling organizations, through fraudulent GitHub repository invitations paired with malicious npm package dependencies. Checkmarx subsequently confirmed the activity was tied to Jade Sleet, TraderTraitor, and the broader Lazarus Group, describing what it assessed as the first nation-state use of open-source supply chain infiltration: attackers built rapport with targets through fake developer and recruiter personas on LinkedIn, Slack, and Telegram before inviting them to collaborate on repositories containing paired first- and second-stage npm packages that were progressively refined with additional obfuscation and more robust error handling. Indicators from the campaign overlapped with the contemporaneous compromise of IT management firm JumpCloud, and the group used compromised developer trust and reputation to reach cryptocurrency and blockchain sector victims.
Midnight Neptune is Google Threat Intelligence Group’s name for a North Korean actor formerly tracked as UNC1069. GTIG attributed the cluster to a March 2026 software supply-chain compromise involving the legitimate axios package. After social engineering compromised a maintainer account, the attacker introduced a malicious dependency that acted as a dropper for the WAVESHAPER.V2 backdoor. The affected versions remained available on npm for less than three hours, but the package’s enormous installation base and downstream dependency relationships created potentially broad exposure. GTIG assisted affected customers across at least fifteen industries and thirteen countries. The operation places Midnight Neptune within a growing pattern of North Korean activity targeting open-source repositories and software-development ecosystems, using trusted package relationships and compromised maintainers to distribute malicious code at scale rather than approaching every victim directly.
Microsoft identified Moonstone Sleet in May 2024 as a new, distinct North Korean state-aligned threat actor, previously tracked under the temporary designation Storm-1789; while it initially overlapped heavily with the actor Diamond Sleet, reusing malware such as Comebacker and similar social-engineering delivery methods, it has since moved to its own dedicated infrastructure and tooling. Moonstone Sleet pursues both espionage and revenue-generation objectives against organizations in the software and information technology, education, and defense-industrial-base sectors. Its tradecraft includes distributing trojanized versions of legitimate software such as PuTTY through platforms like LinkedIn and Telegram; creating fake companies, including ones posing as software-development or IT-consulting firms, to solicit collaboration or job applicants; distributing a malicious blockchain-themed game to deliver a custom malware loader; delivering malware disguised as npm-based technical skills assessments; pursuing employment as remote IT workers at legitimate companies; and, beginning in April 2024, deploying custom ransomware against a previously compromised defense-technology company for financial gain, marking the group's first observed use of ransomware.
PolinRider is the name OpenSourceMalware gave to a 2026 supply-chain campaign it attributes to a North Korean, Lazarus Group-linked threat actor that implants malicious JavaScript into open-source projects on GitHub and npm. Researchers describe it as a parallel or sub-campaign of the broader Contagious Interview activity, noting it initially made use of credentials stolen through a related campaign called TasksJacker. The threat actor forks popular repositories or compromises developers' own repositories, then appends obfuscated JavaScript to frequently executed but rarely reviewed build and configuration files, such as PostCSS, Tailwind CSS, and ESLint configuration files, as well as hiding payloads inside font files. Malicious npm packages were also published to distribute the same payload. The campaign primarily compromises individual, often job-seeking, software developers rather than organizations, and researchers observed its confirmed footprint of poisoned repositories grow substantially between March and July 2026, with targeting spanning ecosystems including Visual Studio Code, Apache Superset, Rails, LangFlow, and Expo.
Pungsan is a cluster that Datadog's Security Research team named 'Stressed Pungsan' after discovering it in July 2024, assessing that its tactics, infrastructure, and targeting align closely with what Microsoft tracks as Moonstone Sleet, a DPRK-aligned actor. Datadog identified the cluster through its open-source package-scanning tooling, which flagged two malicious npm packages published to the npm registry on the same day in July 2024 by a since-removed publishing account. The packages copied code from a popular, legitimate open-source configuration library and added a preinstall script that downloaded a file disguised as a data file, renamed it into a Windows dynamic-link library, and loaded it into memory using a trusted system binary, a technique used to evade detection while gaining a foothold in developer and Windows environments. Consistent with broader Pyongyang-aligned software-supply-chain activity, this actor's post-compromise objective is to steal personal information and API or cloud-access keys and to move laterally into connected environments.
Sapphire Sleet is a North Korean state actor that Microsoft named in April 2023 under its weather-themed taxonomy, replacing an earlier internal codename; Microsoft's naming reference also links it to Genie Spider and BlueNoroff. Microsoft has separately assessed the actor as active since at least March 2020, targeting the financial sector, including cryptocurrency, venture capital, and blockchain organizations, with the goal of stealing cryptocurrency wallets and related intellectual property. Its core playbook is social-engineering-led: operators create fake recruiter personas on social media and professional networking sites, engage targets about job opportunities, and direct them to install software disguised as video-conferencing tools or SDK updates. On macOS this has evolved into a multi-stage AppleScript intrusion chain using cascading script-to-interpreter payload delivery, fake system password dialogs to harvest credentials, manipulation of macOS permission databases to bypass user consent, and persistence mechanisms, culminating in exfiltration of browser data, cryptocurrency wallets, messaging-app sessions, SSH keys, and notes. The group has also run large-scale software-supply-chain compromises, including poisoning more than 140 npm packages with a typosquatted dependency that deployed a dropper and follow-on backdoors.
Storm-1789 was Microsoft’s temporary designation for the North Korean activity cluster that the company renamed Moonstone Sleet in May 2024. Microsoft initially observed the cluster overlapping with Diamond Sleet through reused Comebacker code and delivery of trojanized software over social media, but later separated it after the actor adopted bespoke infrastructure and conducted concurrent operations. Under its mature identity, the group pursued both espionage and revenue generation by creating fake software and blockchain companies, impersonating recruiters and developers, distributing malicious npm packages and trojanized applications, operating a weaponized tank game, seeking legitimate IT employment, and deploying FakePenny ransomware. It targeted software developers, education organizations, defense technology companies, drone manufacturers, and aircraft-parts companies. The transition from Storm-1789 to Moonstone Sleet therefore reflects Microsoft’s evolution from provisional activity tracking to recognition of a distinct and well-resourced actor.
Datadog Security Research disclosed in August 2024 a malicious npm package cluster it internally designates Stressed Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. On July 7, 2024, an npm user published two malicious packages that copied a popular open-source Node.js configuration library and added a pre-install script which downloaded and executed, via a living-off-the-land binary, a malicious DLL retrieved from an attacker-controlled server. Datadog assessed that the tactics, techniques, procedures, and command-and-control infrastructure used in this campaign closely align with activity that Microsoft tracks as the North Korean actor Moonstone Sleet. The malicious packages were removed from the npm registry only hours after publication, a pattern Datadog noted this actor uses to publish quickly and evade detection, and the publishing account had no other prior packages. The campaign reflects continued DPRK-aligned abuse of open-source software supply chains, specifically npm, to gain initial access into developer and cloud environments.
Incidents (6)
Reports (10 of 96)
SafeDep uncovered an npm dependency chain in which `ioredis-xyz` silently resolved `redis-type-xyz` and then the malicious `ulid-xyz` package, whose postinstall hook launched a cross-platform remote access trojan. The implant persisted as MicrosoftSystem6…
PolinRider operators compromised a legitimate developer's GitHub identity and repeatedly used it to distribute DPRK-attributed NullReceiver malware through `fetch-page-assets` and other npm packages. Although npm removed version 1.2.9, the underlying `.vs…
Six npm packages delivered an identical JavaScript loader, including three hijacked legitimate packages and three packages published with the malware already embedded. The loader used an Ethereum transaction as a dead drop, decoding command-and-control IP…
DPRK's PolinRider campaign automatically poisoned legitimate npm packages and Go modules after compromising developer machines, rather than deliberately selecting high-value packages for account takeover. OpenSourceMalware linked 20 analyzed packages thro…
Two malicious beta releases in the legitimate `@joyfill` npm scope executed an obfuscated loader when applications imported their production bundles. The loader resolved encrypted payloads through two successive Tron-to-BSC transaction chains, selected C2…
Two Joyfill beta packages contained an import-time JavaScript implant that used Tron, Aptos, and BNB Smart Chain transactions to resolve mutable payloads. The recovered chain delivered a DEV#POPPER Node.js RAT capable of remote command execution, file tra…
Malicious prerelease builds of `@joyfill/components` and `@joyfill/layouts` executed an obfuscated Node.js loader when imported, bypassing protections focused on npm installation scripts. The implant used blockchain transactions to resolve later stages, d…
Two Joyfill npm prereleases published on 2026-07-28 contained an obfuscated DEV#POPPER-family RAT that executed when applications imported the packages, bypassing protections focused on npm install scripts. The implant obtained rotating command-and-contro…
Checkmarx identified seven malicious npm packages that impersonated Vite-related scopes and delivered an obfuscated remote-access trojan through Tron, Aptos, and Binance Smart Chain infrastructure. Shared wallets, XOR keys, loader structure, and payloads …
`nodemon-sudo` v3.1.16 is a malicious npm lookalike that copies legitimate nodemon while adding an unused dependency on `tslint-conf`, a repackaged pino logger containing the backdoor. The payload avoids install hooks and import-time execution; it runs on…
Tags (1)
NPM
Vulnerability/Target
npm is the Node Package Manager ecosystem used to publish and install JavaScript software packages. DPRK-linked operators have socially engineered maintainers, hijacked legitimate packages, and published malicious or typosquatted packages that execute loaders, steal credentials, establish remote access, and retrieve command-and-control information through public blockchains.