Github를 통해 유포된 VSCode 악용 Contagious Interview 캠페인

2026-02-26 ENKI Contagious Interview Campaign Abusing VSCode Distributed via GitHub

https://www.enki.co.kr/media-center/blog/contagious-interview-campaign-abusing-vscode-distributed-on-github

Thumbnail for Github를 통해 유포된 VSCode 악용 Contagious Interview 캠페인

ENKI found a Contagious Interview campaign using GitHub repositories and VSCode task automation to infect developers with Beavertail, InvisibleFerret, and OtterCookie-related tooling. The operators posed as recruiters, developers, and fictitious or lookalike companies, including Web3-themed personas, then embedded malicious VSCode task files that executed downloaders when victims opened the project folder. The infection chain used OS-specific scripts, Node.js and Python payload staging, obfuscated JavaScript loaders, and C2 infrastructure that delivered Beavertail, collected browser and wallet-related data, and enabled further remote-access and file-exfiltration functions. The report also notes signs that some downloader code may have been generated with LLM assistance and provides infrastructure and GitHub-account details useful for detecting developer-targeted DPRK activity.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://veneliteus.com 2026-02-26 2026-02-26
DOMAIN koinos.io 2026-02-26 2026-02-26
DOMAIN veneliteus.com 2026-02-26 2026-02-26
IPv4 66.235.11.117 2026-02-26 2026-02-26
IPv4 66.235.175.117 2026-01-21 2026-02-26
IPv4 216.250.251.87 2026-01-12 2026-02-26

Related Actors

Related Reports

« Back