CYBERRAKSHAK LABS Β· RESEARCH #054

🚨 DPRK Fake Job Interviews: How a Coding Test Can Become a Malware Attack

A developer can reject an obvious malware attachment yet still execute malicious code when it arrives as a legitimate-looking coding interview. This research examines the DPRK-linked Contagious Interview workflow and the technical chain documented in public research.

By Vivek Kumar Β· Published 7 October 2026
RESEARCH#054
CATEGORYMalware / Social Engineering / Developer Security
CRL ASSESSMENTHIGH
RESEARCH LEVELDeep Research
PUBLISHED2026-10-07
Source & social links:
LinkedIn Post β†—WhatsApp β†—YouTube β†—
How CyberRakshakLabs researches threats β†’
What if the most dangerous file in a job interview is the coding assignment itself?
In the Contagious Interview campaign, a professional-looking repository can become the delivery mechanism for hidden malware targeting developer credentials, crypto wallets, local files and clipboard data.
DPRK-LINKEDCampaign context
4-STAGEObserved payload chain
DEVELOPERPrimary target group
Important: Treat coding assignments, repositories and development environments as untrusted until the recruiter, repository provenance, dependencies and execution behavior are independently validated.
1. Executive Summary

The dangerous part of this campaign is the credibility of the workflow. A victim may believe they are reviewing a normal software project, installing dependencies or completing a coding assignment for a real employer. The repository can function normally while malicious code executes in the background.

Elastic Security Labs reported a July 2026 Contagious Interview campaign in which fake recruiters used developer communities and direct messages to deliver trojanized coding projects. Elastic observed payloads hidden in SVG flag images and a four-stage payload aligned with OTTERCOOKIE.

The Australian Cyber Security Centre identifies WaterPlum, commonly referred to as Contagious Interview, as a North Korean cyber actor group targeting IT professionals. The supplied research therefore supports a high-priority developer-security warning, while the exact victim, lure and compromise path of any individual case still need case-specific validation.

2. Human Attack Story β€” Why the Interview Feels Safe

1. Fake opportunity: an attractive developer role, freelance task or collaboration.

2. Trust building: conversation moves into direct messages and becomes personalized.

3. Technical assessment: the victim receives a coding challenge or repository.

4. Execution pressure: the victim is encouraged to run the project, install dependencies or open it in a development environment.

5. Silent activation: project code reconstructs a hidden payload and launches it.

6. Compromise: browser credentials, wallet data, local files and clipboard contents may be targeted, while a Socket.IO component can provide interactive access.

3. Attack Flow
FAKE JOB→RECRUITER CONTACT→TECHNICAL INTERVIEW→TROJANIZED CODING CHALLENGE→GIT REPOSITORY→SVG FLAG FILES→HIDDEN PAYLOAD→REASSEMBLY / DECODE→MULTI-STAGE MALWARE→CREDENTIAL & WALLET THEFT→FILE / CLIPBOARD THEFT→SOCKET.IO REMOTE ACCESS

The sequence above follows the workflow specified in the supplied research. It is an analytical reconstruction of the documented campaign, not a claim that every stage is observed in every victim environment.

4. SVG Steganography β€” When an Image Becomes a Payload Container

SVG is XML-based and can contain text and markup. In the observed campaign, multiple flag SVGs contained Base64 fragments inside HTML comments. A JavaScript routine read the SVGs in sorted order, extracted the comments, joined the fragments, decoded them and passed the result into execution.

SVG flag files β†’ HTML comments β†’ Base64 fragments β†’ sorted extraction β†’ reassembly β†’ decode β†’ execution

The security lesson is simple: a visible image can look harmless while the same file also carries data that is operationally meaningful to the program loading it.

Elastic says the specific infection chain was newly documented by its team and that the resulting payloads shared technical and behavioral similarities with OTTERCOOKIE.

5. What the Malware Can Target
TargetObserved / Reported Behavior
Browser credentialsSaved browser Login Data and autofill-related data.
Cryptocurrency walletsBrowser wallet extension stores.
Developer filesDocuments, source files, configuration files and shell histories.
ClipboardClipboard changes on Windows and macOS.
Remote accessSocket.IO-based RAT with interactive command capability.
Second-stage payloadsWindows component attempted additional downloads; exact payloads were not confirmed.
6. Warning Signs for Developers and Job Seekers
⚠️ Recruiter pushes you to run code before the employer is independently verified.
⚠️ Repository arrives as a ZIP/RAR or through an unusual personal account.
⚠️ Interview task requires npm install, scripts, PowerShell, batch files or other execution before review.
⚠️ Unknown .vscode/tasks.json or package lifecycle scripts contain download/execute commands.
⚠️ You are asked to disable security controls.
⚠️ node.exe, PowerShell, curl or scripting utilities appear immediately after running the project.
⚠️ Unexpected outbound connections or credential-store access occur after execution.
7. What Developers and Job Seekers Should Do
βœ“ Never run an interview project on your primary workstation.
βœ“ Use an isolated VM or disposable environment without production credentials or crypto wallets.
βœ“ Review package.json scripts and .vscode/tasks.json before installation or launch.
βœ“ Use VS Code Restricted Mode for unknown projects and do not trust unfamiliar folders.
βœ“ Verify the recruiter/employer through an independent channel.
βœ“ Never enter passwords, seed phrases, API keys or SSH credentials into a test project.
βœ“ If execution occurred, isolate the endpoint and rotate credentials from a clean device.
βœ“ If persistence cannot be ruled out, rebuild/reset the endpoint and investigate the environment.

The Australian advisory also recommends disconnecting suspected devices, assuming sensitive data may already have been exfiltrated, creating a new wallet on a separate device where relevant, resetting systems, using EDR and using VS Code Restricted Mode for unknown projects.

8. Threat Intelligence β€” Publicly Reported Indicators
TypeIndicatorContext
Domainrightwidth[.]devOTTERCOOKIE C2
Domainldb.rightwidth[.]devBrowser/wallet stealer C2
Domainupload.rightwidth[.]devFile-stealer upload C2
Domaincontroller.rightwidth[.]devSocket.IO RAT C2
Domainfile.rightwidth[.]devWindows second-stage host
IPv4195.26.248[.]212OTTERCOOKIE C2
IPv4188.40.64[.]61OTTERCOOKIE C2

These are public research observables, not proof that every connection is malicious. Validate them with endpoint, DNS, proxy and process telemetry before treating an observed match as an incident.

9. Public Sample Hashes
SHA-256Sample
8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1eecommerce-main.zip
3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3cnext-ecommerce-private-main.zip
4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864shopping-platform-main.zip
54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9ecommerce-platform.zip
96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20shop-main.zip

The hashes are reproduced from the supplied research document and should be treated as public research observables. Validate against your own telemetry and sample provenance before using them for incident attribution.

10. MITRE ATT&CK Coverage
TechniqueRelevance
T1027.003 – SteganographyPayload fragments concealed in SVG comments.
T1555 – Credentials from Password StoresBrowser credential stores targeted.
T1005 – Data from Local SystemDeveloper files collected.
T1115 – Clipboard DataClipboard collection.
T1083 – File and Directory DiscoveryDrive/file enumeration.
T1082 – System Information DiscoveryHost information and VM checks.
T1071.001 – Web ProtocolsHTTP/HTTPS C2 and exfiltration.
T1041 – Exfiltration Over C2 ChannelStolen data transferred to C2.

Elastic explicitly maps the observed activity to these techniques and related tactics. This mapping describes the public research context; it is not evidence that every technique occurred on every victim.

11. SOC Hunting & DFIR Priorities
πŸ”Ž Review endpoint process trees after project execution, especially node.exe, PowerShell, curl and unexpected child processes.
πŸ”Ž Inspect DNS/proxy telemetry for the public C2 observables and validate process-to-network relationships.
πŸ”Ž Review browser credential-store access, wallet-extension paths, clipboard activity and developer-file access for the affected host.
πŸ”Ž Check package.json scripts, .vscode/tasks.json and project startup paths before executing unfamiliar repositories.
πŸ”Ž If compromise is suspected, isolate the endpoint and rotate credentials from a clean device; rebuild/reset when persistence cannot be ruled out.

The best detection strategy is behavioral correlation. A single DNS hit is weaker evidence than a sequence linking a repository execution event, suspicious child process creation, credential-store access and outbound communication to infrastructure associated with the campaign.

12. CyberRakshakLabs Assessment
CyberRakshakLabs Assessment: HIGH
The primary risk is the trust layer. A recruiter can be fake, a repository can be cloned or modified, and an image file can carry hidden content. Developers should treat every take-home assignment as untrusted code until employer identity, repository provenance, dependencies and execution behavior are independently validated.
A coding interview is still executable software. Verify it before you run it.
13. LinkedIn / Channel Summary

A job interview can become an initial-access vector. DPRK-linked Contagious Interview activity shows how attackers can approach developers with convincing job offers, deliver a normal-looking coding challenge and hide malicious payloads inside SVG flag images. Once executed, the chain can target browser credentials, crypto wallets, local files and clipboard data while establishing remote access. A coding challenge is still executable codeβ€”verify it before you run it.

14. Sources & Verification Notes