North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads

2026-04-07 Socket

https://socket.dev/blog/contagious-interview-campaign-spreads-across-5-ecosystems

Thumbnail for North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads

Socket identifies a new cluster in North Korea’s Contagious Interview operation that published malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist. The packages impersonated developer tools while hiding loaders inside ordinary-looking logging, license, tracing, multipart parsing, and helper functions rather than relying mainly on install-time execution. Shared staging behavior included contacting attacker-controlled infrastructure such as apachelicense[.]vercel[.]app, ngrok-free[.]vercel[.]app, logkit.onrender[.]com, logkit-tau[.]vercel[.]app, 66[.]45[.]225[.]94, and Google Drive delivery links to fetch ZIP archives or remotely supplied code. The payloads targeted developer environments for credential, browser, password-manager, and cryptocurrency wallet theft, with license-utils-kit adding Windows post-compromise functions including shell execution, keylogging, AnyDesk deployment, sensitive-file collection, encrypted archiving, and additional module execution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9a541dffb7fc18dc71dbc8523ec6c3a… 2026-04-07 2026-04-07
HASH bb2a89001410fa5a11dea6477d4f557… 2026-04-07 2026-04-07
HASH 7c5adef4b5aee7a4aa6e795a86f8b7d… 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
EMAIL [email protected] 2026-04-07 2026-04-07
URL https://apachelicense.vercel.ap… 2026-04-07 2026-04-07
DOMAIN logkit.onrender.com 2026-04-07 2026-04-07
IPv4 66.45.225.94 2026-04-07 2026-04-07

Related Actors

Related Reports

« Back