North Korea’s Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads
2026-04-07 • Socket •
https://socket.dev/blog/contagious-interview-campaign-spreads-across-5-ecosystems
Socket identifies a new cluster in North Korea’s Contagious Interview operation that published malicious packages across npm, PyPI, Go Modules, crates.io, and Packagist. The packages impersonated developer tools while hiding loaders inside ordinary-looking logging, license, tracing, multipart parsing, and helper functions rather than relying mainly on install-time execution. Shared staging behavior included contacting attacker-controlled infrastructure such as apachelicense[.]vercel[.]app, ngrok-free[.]vercel[.]app, logkit.onrender[.]com, logkit-tau[.]vercel[.]app, 66[.]45[.]225[.]94, and Google Drive delivery links to fetch ZIP archives or remotely supplied code. The payloads targeted developer environments for credential, browser, password-manager, and cryptocurrency wallet theft, with license-utils-kit adding Windows post-compromise functions including shell execution, keylogging, AnyDesk deployment, sensitive-file collection, encrypted archiving, and additional module execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9a541dffb7fc18dc71dbc8523ec6c3a… | 2026-04-07 | 2026-04-07 |
| HASH | bb2a89001410fa5a11dea6477d4f557… | 2026-04-07 | 2026-04-07 |
| HASH | 7c5adef4b5aee7a4aa6e795a86f8b7d… | 2026-04-07 | 2026-04-07 |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| [email protected] | 2026-04-07 | 2026-04-07 | |
| URL | https://apachelicense.vercel.ap… | 2026-04-07 | 2026-04-07 |
| DOMAIN | logkit.onrender.com | 2026-04-07 | 2026-04-07 |
| IPv4 | 66.45.225.94 | 2026-04-07 | 2026-04-07 |