Contagious Interview gets an upgrade for 2026

2026-01-20 OSM

https://opensourcemalware.com/blog/contagious-interview-comprehensive

OpenSourceMalware traced the malicious npm package tailwindcss-forms-kit to the DPRK-linked Contagious Interview campaign, where fake recruiters target software engineers in cryptocurrency, Web3, and blockchain roles. The package masqueraded as a Tailwind utility, then fetched heavily obfuscated JavaScript from api.npoint.io and connected to 95.216.37.186:5000 over Socket.IO for registration, file upload, tasking, and command execution. The payload harvested browser passwords, macOS keychains, shell history, cloud credential directories, sensitive files, and cryptocurrency wallet data from browser extensions and desktop wallets. Windows persistence used an HKCU Run key named NvidiaDriverUpdate, giving the operators continued access after the initial social-engineering-driven package execution.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.216.37.186 2026-01-20 2026-04-01
IPv4 95.164.17.24 2024-07-15 2026-04-01
DOMAIN ip-api.com 2022-11-14 2026-01-21
HASH 699cd6c292b8a5933dabee63c74a9a3… 2026-01-20 2026-01-20
HASH 153e2f27e035252d5f7ace69948e80b2 2026-01-20 2026-01-20
HASH 1c8c1a693209c310e9089eb2d5713dc… 2026-01-20 2026-01-20
HASH 5a2c042b086a475dca4c7dcec62693c1 2026-01-20 2026-01-20
URL https://api.npoint.io/9d94ec605… 2026-01-20 2026-01-20
HASH eba9fdb2f077f9a3e14cf428162b967… 2025-09-17 2026-01-20
URL http://ip-api.com/json 2024-07-31 2026-01-20

Related Actors

Related Reports

« Back