In the Contagious Interview campaign, a professional-looking repository can become the delivery mechanism for hidden malware targeting developer credentials, crypto wallets, local files and clipboard data.
1. Executive Summary
The dangerous part of this campaign is the credibility of the workflow. A victim may believe they are reviewing a normal software project, installing dependencies or completing a coding assignment for a real employer. The repository can function normally while malicious code executes in the background.
Elastic Security Labs reported a July 2026 Contagious Interview campaign in which fake recruiters used developer communities and direct messages to deliver trojanized coding projects. Elastic observed payloads hidden in SVG flag images and a four-stage payload aligned with OTTERCOOKIE.
The Australian Cyber Security Centre identifies WaterPlum, commonly referred to as Contagious Interview, as a North Korean cyber actor group targeting IT professionals. The supplied research therefore supports a high-priority developer-security warning, while the exact victim, lure and compromise path of any individual case still need case-specific validation.
2. Human Attack Story β Why the Interview Feels Safe
1. Fake opportunity: an attractive developer role, freelance task or collaboration.
2. Trust building: conversation moves into direct messages and becomes personalized.
3. Technical assessment: the victim receives a coding challenge or repository.
4. Execution pressure: the victim is encouraged to run the project, install dependencies or open it in a development environment.
5. Silent activation: project code reconstructs a hidden payload and launches it.
6. Compromise: browser credentials, wallet data, local files and clipboard contents may be targeted, while a Socket.IO component can provide interactive access.
3. Attack Flow
The sequence above follows the workflow specified in the supplied research. It is an analytical reconstruction of the documented campaign, not a claim that every stage is observed in every victim environment.
4. SVG Steganography β When an Image Becomes a Payload Container
SVG is XML-based and can contain text and markup. In the observed campaign, multiple flag SVGs contained Base64 fragments inside HTML comments. A JavaScript routine read the SVGs in sorted order, extracted the comments, joined the fragments, decoded them and passed the result into execution.
SVG flag files β HTML comments β Base64 fragments β sorted extraction β reassembly β decode β executionThe security lesson is simple: a visible image can look harmless while the same file also carries data that is operationally meaningful to the program loading it.
Elastic says the specific infection chain was newly documented by its team and that the resulting payloads shared technical and behavioral similarities with OTTERCOOKIE.
5. What the Malware Can Target
| Target | Observed / Reported Behavior |
|---|---|
| Browser credentials | Saved browser Login Data and autofill-related data. |
| Cryptocurrency wallets | Browser wallet extension stores. |
| Developer files | Documents, source files, configuration files and shell histories. |
| Clipboard | Clipboard changes on Windows and macOS. |
| Remote access | Socket.IO-based RAT with interactive command capability. |
| Second-stage payloads | Windows component attempted additional downloads; exact payloads were not confirmed. |
6. Warning Signs for Developers and Job Seekers
7. What Developers and Job Seekers Should Do
The Australian advisory also recommends disconnecting suspected devices, assuming sensitive data may already have been exfiltrated, creating a new wallet on a separate device where relevant, resetting systems, using EDR and using VS Code Restricted Mode for unknown projects.
8. Threat Intelligence β Publicly Reported Indicators
| Type | Indicator | Context |
|---|---|---|
| Domain | rightwidth[.]dev | OTTERCOOKIE C2 |
| Domain | ldb.rightwidth[.]dev | Browser/wallet stealer C2 |
| Domain | upload.rightwidth[.]dev | File-stealer upload C2 |
| Domain | controller.rightwidth[.]dev | Socket.IO RAT C2 |
| Domain | file.rightwidth[.]dev | Windows second-stage host |
| IPv4 | 195.26.248[.]212 | OTTERCOOKIE C2 |
| IPv4 | 188.40.64[.]61 | OTTERCOOKIE C2 |
These are public research observables, not proof that every connection is malicious. Validate them with endpoint, DNS, proxy and process telemetry before treating an observed match as an incident.
9. Public Sample Hashes
| SHA-256 | Sample |
|---|---|
| 8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e | ecommerce-main.zip |
| 3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c | next-ecommerce-private-main.zip |
| 4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864 | shopping-platform-main.zip |
| 54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9 | ecommerce-platform.zip |
| 96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20 | shop-main.zip |
The hashes are reproduced from the supplied research document and should be treated as public research observables. Validate against your own telemetry and sample provenance before using them for incident attribution.
10. MITRE ATT&CK Coverage
| Technique | Relevance |
|---|---|
| T1027.003 β Steganography | Payload fragments concealed in SVG comments. |
| T1555 β Credentials from Password Stores | Browser credential stores targeted. |
| T1005 β Data from Local System | Developer files collected. |
| T1115 β Clipboard Data | Clipboard collection. |
| T1083 β File and Directory Discovery | Drive/file enumeration. |
| T1082 β System Information Discovery | Host information and VM checks. |
| T1071.001 β Web Protocols | HTTP/HTTPS C2 and exfiltration. |
| T1041 β Exfiltration Over C2 Channel | Stolen data transferred to C2. |
Elastic explicitly maps the observed activity to these techniques and related tactics. This mapping describes the public research context; it is not evidence that every technique occurred on every victim.
11. SOC Hunting & DFIR Priorities
The best detection strategy is behavioral correlation. A single DNS hit is weaker evidence than a sequence linking a repository execution event, suspicious child process creation, credential-store access and outbound communication to infrastructure associated with the campaign.
12. CyberRakshakLabs Assessment
The primary risk is the trust layer. A recruiter can be fake, a repository can be cloned or modified, and an image file can carry hidden content. Developers should treat every take-home assignment as untrusted code until employer identity, repository provenance, dependencies and execution behavior are independently validated.
13. LinkedIn / Channel Summary
A job interview can become an initial-access vector. DPRK-linked Contagious Interview activity shows how attackers can approach developers with convincing job offers, deliver a normal-looking coding challenge and hide malicious payloads inside SVG flag images. Once executed, the chain can target browser credentials, crypto wallets, local files and clipboard data while establishing remote access. A coding challenge is still executable codeβverify it before you run it.
14. Sources & Verification Notes
Australian Cyber Security Centre β WaterPlum / Contagious Interview advisory
Kudelski Security Research β How DPRKβs Contagious Interview Campaign Targets Developers
Primary basis: supplied CyberRakshakLabs research document. Claims about any individual victim or breach scope must be independently validated.