DPRK-linked Contagious Interview campaign turns Web3 job tests into wallet-stealing malware


3 recorded changes
Want your article here?
Promote with Leviathan News

3 recorded changes
Want your article here?
Promote with Leviathan NewsThe Contagious Interview campaign, attributed to Lazarus/APT38-style DPRK-linked actors, uses fake Web3 recruiting flows to make developers run malware disguised as take-home tests. The lure is polished: LinkedIn outreach, PDFs/Figma boards, Google Meet interviews, then GitHub/Bitbucket repos, OneDrive downloads, npm postinstall hooks, obfuscated WASM, or fake meeting tools aimed at wallets, seed phrases, browser creds, and company access. MetaLamp says it dodged one after spotting a suspicious Bitbucket repo and a 17-day-old npm package executing `eval(JSON.parse(b))`, the kind of payload that can turn one careless `npm install` into a full compromise.
TLDR by @Benthic

𝕏/@0xAbhiP ·

𝕏/@officer_secret ·

decrypt.co ·

𝕏/@TheBlockCo ·

CoinTelegraph ·

𝕏/@a16zcrypto ·

𝕏/@0xAbhiP ·

𝕏/@officer_secret ·

decrypt.co ·

𝕏/@TheBlockCo ·

CoinTelegraph ·

𝕏/@a16zcrypto ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?