← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
North Korea's Contagious Interview Campaign Spreads Across 5 Ecosystems, Delivering Staged RAT Payloads
We have been tracking North Korea’s Contagious Interview operation since 2024 and maintain a dedicated campaign page that now tracks more than 1,700 malicious packages linked to the activity. In this newly identified cluster, the threat actors operated under GitHub aliases including golangorg and published malicious packages across five open source ecosystems. The threat actor’s packages were designed to impersonate legitimate developer tooling (such as debug, debug-logfmt, pino-debug, baraka, license, http, libprettylogger, and openlss/func-log), while quietly functioning as malware loaders, extending Contagious Interview’s established playbook into a coordinated cross-ecosystem supply chain operation.
MITRE ATT&CK & Malware Families
Indicators of Compromise (4)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 7c5adef4b5aee7a4aa6e795a86f8b7d601618c3bc003f1326ca57d03ec7d6524 | — | 2026-04-08 | |
| FileHash-SHA256 | 9a541dffb7fc18dc71dbc8523ec6c3a71c224ffeb518ae3a8d7d16377aebee58 | — | 2026-04-08 | |
| FileHash-SHA256 | bb2a89001410fa5a11dea6477d4f5573130261badc67fe952cfad1174c2f0edd | — | 2026-04-08 | |
| domain | self.run | — | 2026-04-08 |