New DPRK Contagious Interview Campaign: “Fake Font” Uses Malicious VSCode Fonts
2026-01-28 • OSM •
https://opensourcemalware.com/blog/contagious-code-fake-font
OpenSourceMalware identified a Lazarus Group variation of the Contagious Interview campaign that targets software engineers through fake recruiter outreach and GitHub coding assessments. The attack abuses VS Code task automation with runOn: folderOpen to execute a JavaScript file disguised as a Font Awesome .woff2 font when the victim opens the project. The obfuscated BeaverTail-style loader uses Base91-encoded strings, creates a hidden ~/.npm scoped directory, installs Node dependencies, and contacts the fake Alchemy-themed domain eth-mainnet-alchemy.com. Code returned from the C2 is executed through new Function(), and the chain is reported to deliver the InvisibleFerret Python backdoor for cryptocurrency wallet theft, browser credential theft, and persistent access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f71d1d9b2de7d4ebf5f706a4b9cd4eb4 | 2026-01-28 | 2026-01-28 |
| URL | http://eth-mainnet-alchemy.com/… | 2026-01-28 | 2026-01-28 |
| URL | http://eth-mainnet-alchemy.com/… | 2026-01-28 | 2026-01-28 |
| URL | http://eth-mainnet-alchemy.com | 2026-01-28 | 2026-01-28 |
| DOMAIN | eth-mainnet.alchemyapi.io | 2026-01-28 | 2026-01-28 |
| DOMAIN | eth-mainnet-alchemy.com | 2026-01-28 | 2026-01-28 |