New DPRK Contagious Interview Campaign: “Fake Font” Uses Malicious VSCode Fonts

2026-01-28 OSM

https://opensourcemalware.com/blog/contagious-code-fake-font

Thumbnail for New DPRK Contagious Interview Campaign: “Fake Font” Uses Malicious VSCode Fonts

OpenSourceMalware identified a Lazarus Group variation of the Contagious Interview campaign that targets software engineers through fake recruiter outreach and GitHub coding assessments. The attack abuses VS Code task automation with runOn: folderOpen to execute a JavaScript file disguised as a Font Awesome .woff2 font when the victim opens the project. The obfuscated BeaverTail-style loader uses Base91-encoded strings, creates a hidden ~/.npm scoped directory, installs Node dependencies, and contacts the fake Alchemy-themed domain eth-mainnet-alchemy.com. Code returned from the C2 is executed through new Function(), and the chain is reported to deliver the InvisibleFerret Python backdoor for cryptocurrency wallet theft, browser credential theft, and persistent access.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f71d1d9b2de7d4ebf5f706a4b9cd4eb4 2026-01-28 2026-01-28
URL http://eth-mainnet-alchemy.com/… 2026-01-28 2026-01-28
URL http://eth-mainnet-alchemy.com/… 2026-01-28 2026-01-28
URL http://eth-mainnet-alchemy.com 2026-01-28 2026-01-28
DOMAIN eth-mainnet.alchemyapi.io 2026-01-28 2026-01-28
DOMAIN eth-mainnet-alchemy.com 2026-01-28 2026-01-28

Related Actors

Related Reports

« Back