Contagious Interview Campaign Escalates With 67 Malicious npm Packages and New Malware Loader
2025-07-15 • Socket •
https://socket.dev/blog/contagious-interview-campaign-escalates-67-malicious-npm-packages
Socket reports that North Korean Contagious Interview operators expanded their software supply-chain activity with 67 malicious npm packages, including 28 tied to the newly identified XORIndex loader and 39 new HexEval packages. XORIndex collects host metadata, posts it to hardcoded /api/ipcheck endpoints, and executes returned JavaScript that can load BeaverTail, with references to the InvisibleFerret third-stage backdoor. The activity targets the Node.js ecosystem, especially developers, job seekers, and people likely to hold cryptocurrency or sensitive credentials. BeaverTail enumerates wallet and browser-extension storage for MetaMask, Coinbase Wallet, Phantom, Exodus, Solana keys, macOS keychain data, and related files, then archives and exfiltrates them to infrastructure such as 144[.]217[.]86[.]88. The report matters because it shows the campaign continuing in parallel loader waves, with live npm packages, thousands of downloads, and rapid re-upload behavior after takedowns.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | outlook.com | 2018-09-06 | 2026-04-17 |
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| URL | https://process-log-update.verc… | 2025-07-15 | 2025-10-10 |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| URL | https://log-writter.vercel.app/… | 2025-07-15 | 2025-07-15 |
| URL | https://1215.vercel.app/api/ipc… | 2025-07-15 | 2025-07-15 |
| URL | https://soc-log.vercel.app/api/… | 2025-07-15 | 2025-07-15 |
| URL | https://api.npoint.io/1f901a22d… | 2025-07-15 | 2025-07-15 |
| DOMAIN | gedu.demo.ta-39.com | 2025-07-15 | 2025-07-15 |
| IPv4 | 144.217.86.88 | 2025-07-15 | 2025-07-15 |