Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader

2025-07-15 Socket

https://socket.dev/blog/contagious-interview-campaign-escalates-67-malicious-npm-packages

Thumbnail for Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader

Socket reports that North Korean Contagious Interview operators expanded their software supply-chain activity with 67 malicious npm packages, including 28 tied to the newly identified XORIndex loader and 39 new HexEval packages. XORIndex collects host metadata, posts it to hardcoded /api/ipcheck endpoints, and executes returned JavaScript that can load BeaverTail, with references to the InvisibleFerret third-stage backdoor. The activity targets the Node.js ecosystem, especially developers, job seekers, and people likely to hold cryptocurrency or sensitive credentials. BeaverTail enumerates wallet and browser-extension storage for MetaMask, Coinbase Wallet, Phantom, Exodus, Solana keys, macOS keychain data, and related files, then archives and exfiltrates them to infrastructure such as 144[.]217[.]86[.]88. The report matters because it shows the campaign continuing in parallel loader waves, with live npm packages, thousands of downloads, and rapid re-upload behavior after takedowns.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN outlook.com 2018-09-06 2026-04-17
DOMAIN ip-api.com 2022-11-14 2026-01-21
URL https://process-log-update.verc… 2025-07-15 2025-10-10
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
EMAIL [email protected] 2025-07-15 2025-07-15
URL https://log-writter.vercel.app/… 2025-07-15 2025-07-15
URL https://1215.vercel.app/api/ipc… 2025-07-15 2025-07-15
URL https://soc-log.vercel.app/api/… 2025-07-15 2025-07-15
URL https://api.npoint.io/1f901a22d… 2025-07-15 2025-07-15
DOMAIN gedu.demo.ta-39.com 2025-07-15 2025-07-15
IPv4 144.217.86.88 2025-07-15 2025-07-15

Related Actors

Related Reports

2025-11-26 • 70% Match
#NPM #ContagiousInterview #OtterCookie #T1082 #T1119 #T1005 #T1587.001 #T1041 #T1113 #T1608.001 #T1195.002 #T1115 #T1083 #T1497 #T1056.001 #T1059.007 #T1036 #T1204.002 #T1555.003 #T1583.006 #T1547.001 #T1539 #T1583.001 #T1656 #T1105 #T1204.005 #T1571 #T1657 #T1587 #T1585 #T1555.001 #T1546.016 #T1217
Shares tags: NPM, ContagiousInterview, T1082 • Shares 1 IOC • Same author: Socket
« Back