Contagious Interview is the name Palo Alto Networks' Unit 42 gave in November 2023 to an ongoing campaign, tracked internally as CL-STA-0240, that Unit 42 attributes with moderate confidence to a North Korea state-sponsored threat actor. Unit 42 found the activity, dating to at least December 2022, poses as employers offering software development jobs, luring victims through fake interviews into installing malicious npm packages hosted on GitHub; this delivers malware Unit 42 named BeaverTail, a cross-platform information stealer and loader, followed by a Python backdoor named InvisibleFerret, with an objective of cryptocurrency theft and establishing footholds for further attacks. Unit 42 has continued to track the campaign's evolution, including a cross-platform BeaverTail variant compiled with the Qt framework in mid-2024. Other researchers, including Datadog, have linked additional malicious npm packages and distinct threat-actor clusters, such as one Datadog separately named Tenacious Pungsan, to the same Contagious Interview activity targeting software and blockchain developers.
Search
Actors (12)
MITRE ATT&CK profiles Moonstone Sleet (G1036) as a North Korea-linked threat actor conducting both financially motivated attacks and espionage operations that previously overlapped significantly with the Lazarus Group before differentiating its tradecraft from 2023 onward. The group is noted for creating fake companies and personas, including social media and email accounts, to engage victim organizations and gather information ahead of intrusions, and for developing unique malware such as a payload delivered through a fully functioning game. Moonstone Sleet has distributed a trojanized version of the PuTTY utility as a software supply chain compromise, developed malicious npm packages, and delivered payloads through spearphishing attachments and social media services. Observed intermediate loaders such as YouieLoader and SplitLoader create malicious services and perform system, network, and browser information discovery, while the group has also dumped credentials from LSASS memory, used scheduled tasks for persistence and execution, and deployed ransomware for impact, reflecting a mixed espionage and financially motivated operational profile.
GitHub disclosed a low-volume social engineering campaign, publicly attributed with high confidence to a group it identified as Jade Sleet per Microsoft Threat Intelligence naming and TraderTraitor per CISA, that targeted personal accounts of technology-industry employees, primarily those connected to blockchain, cryptocurrency, and online gambling organizations, through fraudulent GitHub repository invitations paired with malicious npm package dependencies. Checkmarx subsequently confirmed the activity was tied to Jade Sleet, TraderTraitor, and the broader Lazarus Group, describing what it assessed as the first nation-state use of open-source supply chain infiltration: attackers built rapport with targets through fake developer and recruiter personas on LinkedIn, Slack, and Telegram before inviting them to collaborate on repositories containing paired first- and second-stage npm packages that were progressively refined with additional obfuscation and more robust error handling. Indicators from the campaign overlapped with the contemporaneous compromise of IT management firm JumpCloud, and the group used compromised developer trust and reputation to reach cryptocurrency and blockchain sector victims.
Midnight Neptune is Google Threat Intelligence Group’s name for a North Korean actor formerly tracked as UNC1069. GTIG attributed the cluster to a March 2026 software supply-chain compromise involving the legitimate axios package. After social engineering compromised a maintainer account, the attacker introduced a malicious dependency that acted as a dropper for the WAVESHAPER.V2 backdoor. The affected versions remained available on npm for less than three hours, but the package’s enormous installation base and downstream dependency relationships created potentially broad exposure. GTIG assisted affected customers across at least fifteen industries and thirteen countries. The operation places Midnight Neptune within a growing pattern of North Korean activity targeting open-source repositories and software-development ecosystems, using trusted package relationships and compromised maintainers to distribute malicious code at scale rather than approaching every victim directly.
Microsoft identified Moonstone Sleet in May 2024 as a new, distinct North Korean state-aligned threat actor, previously tracked under the temporary designation Storm-1789; while it initially overlapped heavily with the actor Diamond Sleet, reusing malware such as Comebacker and similar social-engineering delivery methods, it has since moved to its own dedicated infrastructure and tooling. Moonstone Sleet pursues both espionage and revenue-generation objectives against organizations in the software and information technology, education, and defense-industrial-base sectors. Its tradecraft includes distributing trojanized versions of legitimate software such as PuTTY through platforms like LinkedIn and Telegram; creating fake companies, including ones posing as software-development or IT-consulting firms, to solicit collaboration or job applicants; distributing a malicious blockchain-themed game to deliver a custom malware loader; delivering malware disguised as npm-based technical skills assessments; pursuing employment as remote IT workers at legitimate companies; and, beginning in April 2024, deploying custom ransomware against a previously compromised defense-technology company for financial gain, marking the group's first observed use of ransomware.
PolinRider is the name OpenSourceMalware gave to a 2026 supply-chain campaign it attributes to a North Korean, Lazarus Group-linked threat actor that implants malicious JavaScript into open-source projects on GitHub and npm. Researchers describe it as a parallel or sub-campaign of the broader Contagious Interview activity, noting it initially made use of credentials stolen through a related campaign called TasksJacker. The threat actor forks popular repositories or compromises developers' own repositories, then appends obfuscated JavaScript to frequently executed but rarely reviewed build and configuration files, such as PostCSS, Tailwind CSS, and ESLint configuration files, as well as hiding payloads inside font files. Malicious npm packages were also published to distribute the same payload. The campaign primarily compromises individual, often job-seeking, software developers rather than organizations, and researchers observed its confirmed footprint of poisoned repositories grow substantially between March and July 2026, with targeting spanning ecosystems including Visual Studio Code, Apache Superset, Rails, LangFlow, and Expo.
Pungsan is a cluster that Datadog's Security Research team named 'Stressed Pungsan' after discovering it in July 2024, assessing that its tactics, infrastructure, and targeting align closely with what Microsoft tracks as Moonstone Sleet, a DPRK-aligned actor. Datadog identified the cluster through its open-source package-scanning tooling, which flagged two malicious npm packages published to the npm registry on the same day in July 2024 by a since-removed publishing account. The packages copied code from a popular, legitimate open-source configuration library and added a preinstall script that downloaded a file disguised as a data file, renamed it into a Windows dynamic-link library, and loaded it into memory using a trusted system binary, a technique used to evade detection while gaining a foothold in developer and Windows environments. Consistent with broader Pyongyang-aligned software-supply-chain activity, this actor's post-compromise objective is to steal personal information and API or cloud-access keys and to move laterally into connected environments.
Sapphire Sleet is a North Korean state actor that Microsoft named in April 2023 under its weather-themed taxonomy, replacing an earlier internal codename; Microsoft's naming reference also links it to Genie Spider and BlueNoroff. Microsoft has separately assessed the actor as active since at least March 2020, targeting the financial sector, including cryptocurrency, venture capital, and blockchain organizations, with the goal of stealing cryptocurrency wallets and related intellectual property. Its core playbook is social-engineering-led: operators create fake recruiter personas on social media and professional networking sites, engage targets about job opportunities, and direct them to install software disguised as video-conferencing tools or SDK updates. On macOS this has evolved into a multi-stage AppleScript intrusion chain using cascading script-to-interpreter payload delivery, fake system password dialogs to harvest credentials, manipulation of macOS permission databases to bypass user consent, and persistence mechanisms, culminating in exfiltration of browser data, cryptocurrency wallets, messaging-app sessions, SSH keys, and notes. The group has also run large-scale software-supply-chain compromises, including poisoning more than 140 npm packages with a typosquatted dependency that deployed a dropper and follow-on backdoors.
Storm-1789 was Microsoft’s temporary designation for the North Korean activity cluster that the company renamed Moonstone Sleet in May 2024. Microsoft initially observed the cluster overlapping with Diamond Sleet through reused Comebacker code and delivery of trojanized software over social media, but later separated it after the actor adopted bespoke infrastructure and conducted concurrent operations. Under its mature identity, the group pursued both espionage and revenue generation by creating fake software and blockchain companies, impersonating recruiters and developers, distributing malicious npm packages and trojanized applications, operating a weaponized tank game, seeking legitimate IT employment, and deploying FakePenny ransomware. It targeted software developers, education organizations, defense technology companies, drone manufacturers, and aircraft-parts companies. The transition from Storm-1789 to Moonstone Sleet therefore reflects Microsoft’s evolution from provisional activity tracking to recognition of a distinct and well-resourced actor.
Datadog Security Research disclosed in August 2024 a malicious npm package cluster it internally designates Stressed Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. On July 7, 2024, an npm user published two malicious packages that copied a popular open-source Node.js configuration library and added a pre-install script which downloaded and executed, via a living-off-the-land binary, a malicious DLL retrieved from an attacker-controlled server. Datadog assessed that the tactics, techniques, procedures, and command-and-control infrastructure used in this campaign closely align with activity that Microsoft tracks as the North Korean actor Moonstone Sleet. The malicious packages were removed from the npm registry only hours after publication, a pattern Datadog noted this actor uses to publish quickly and evade detection, and the publishing account had no other prior packages. The campaign reflects continued DPRK-aligned abuse of open-source software supply chains, specifically npm, to gain initial access into developer and cloud environments.
SuccessKey is Checkmarx Zero’s designation for the operator of ChainVeil, a malicious npm supply-chain campaign publicly described in June 2026. The actor used the npm account successkeyteck to publish at least nine typosquatted packages containing fourteen malicious versions, targeting JavaScript developers who searched for Tailwind, Sass, TypeORM, and rate-limiting libraries. Malicious code executed when applications imported a package rather than during installation, helping it evade scanners focused on lifecycle scripts. The loader copied metadata from legitimate projects, used layered obfuscation, checked for analysis environments, and resolved rotating payloads through transactions on Tron, Aptos, and Binance Smart Chain. Its final remote-access payload supported interactive shells, arbitrary command and JavaScript execution, file theft, SSH-key and npm-token collection, macOS Keychain access, and hidden persistence in shell configuration files. Infrastructure history indicated a sustained, automated operation beginning by June 2025.
Datadog Security Research disclosed in October 2024 a malicious npm package cluster it designates Tenacious Pungsan, following Datadog's practice of naming DPRK-nexus clusters after dog breeds native to North Korea. In September 2024, Datadog identified three npm packages, backdoored copies of popular open-source authentication and blockchain-API libraries, that together had a few hundred downloads and contained an obfuscated variant of BeaverTail, a JavaScript infostealer and downloader first identified by Palo Alto Networks Unit 42 in late 2023. BeaverTail targets cryptocurrency wallets and stored browser and payment-card data, and downloads a second-stage Python backdoor known as InvisibleFerret. Based on shared command-and-control infrastructure, a reused server directory structure, and consistent malware behavior, Datadog attributed these packages with high confidence to the Contagious Interview campaign, an ongoing DPRK-linked operation that lures technology-industry job seekers into fake interviews where the malware is delivered as a fabricated interview task, indicating this npm supply-chain activity forms part of that broader campaign targeting individual software developers.