#ContagiousTrader
Incident/Operation
2026-03-17 • Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators
Contagious Trader is a DPRK-linked software supply chain campaign active since at least February 2026. It targets cryptocurrency users with poisoned GitHub trading-bot projects and malicious npm packages made to look credible through popular market themes, forks, and stars. The payloads steal private keys, credentials, environment files, shell histories, and other sensitive data; some variants also add an attacker-controlled SSH key for persistent access. Researchers connected the campaign to North Korean tradecraft through operational overlaps with Contagious Interview, and later analysis attributed associated npm activity to FAMOUS CHOLLIMA with high confidence.
-
3
Tagged Reports
-
3
Unique Authors
-
151
Active Days