Contagious Interview gets an upgrade for 2026
2026-01-20 • OSM •
https://opensourcemalware.com/blog/contagious-interview-comprehensive
OpenSourceMalware traced the malicious npm package tailwindcss-forms-kit to the DPRK-linked Contagious Interview campaign, where fake recruiters target software engineers in cryptocurrency, Web3, and blockchain roles. The package masqueraded as a Tailwind utility, then fetched heavily obfuscated JavaScript from api.npoint.io and connected to 95.216.37.186:5000 over Socket.IO for registration, file upload, tasking, and command execution. The payload harvested browser passwords, macOS keychains, shell history, cloud credential directories, sensitive files, and cryptocurrency wallet data from browser extensions and desktop wallets. Windows persistence used an HKCU Run key named NvidiaDriverUpdate, giving the operators continued access after the initial social-engineering-driven package execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.216.37.186 | 2026-01-20 | 2026-04-01 |
| IPv4 | 95.164.17.24 | 2024-07-15 | 2026-04-01 |
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| HASH | 699cd6c292b8a5933dabee63c74a9a3… | 2026-01-20 | 2026-01-20 |
| HASH | 153e2f27e035252d5f7ace69948e80b2 | 2026-01-20 | 2026-01-20 |
| HASH | 1c8c1a693209c310e9089eb2d5713dc… | 2026-01-20 | 2026-01-20 |
| HASH | 5a2c042b086a475dca4c7dcec62693c1 | 2026-01-20 | 2026-01-20 |
| URL | https://api.npoint.io/9d94ec605… | 2026-01-20 | 2026-01-20 |
| HASH | eba9fdb2f077f9a3e14cf428162b967… | 2025-09-17 | 2026-01-20 |
| URL | http://ip-api.com/json | 2024-07-31 | 2026-01-20 |