Fake Coding Tests Deliver OtterCookie Malware Hidden in SVG Flag Images
North Korean threat actors linked to the Contagious Interview campaign have been observed using steganography in SVG image files to conceal malicious…
North Korean threat actors linked to the Contagious Interview campaign have been observed using steganography in SVG image files to conceal malicious…
North Korean threat actors linked to the Contagious Interview campaign have published 108 unique malicious packages and browser extensions across npm, Packagist,…
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup…
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages designed to deploy a Python-based information stealer on…
Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS…
A sophisticated social engineering operation ongoing since at least December 2022, targeting software developers with fake job postings and coding challenges to…
A known JavaScript malware associated with the Contagious Interview campaign. Delivered via malicious packages and extensions, it searches for configuration files and…
[Contagious Interview](https://attack.mitre.org/groups/G1052) is a North Korea–aligned threat group active since 2023. The group conducts both cyberespionage and financially motivated operations, including the…