← Back to Daily Briefing

North Korean-linked threat actors are executing the "Contagious Interview" campaign, targeting developers through fraudulent recruitment. The attack utilizes SVG steganography to embed malicious payloads within graphic assets and leverages malicious npm packages with multi-layer dependency nesting to deliver the OtterCookie infostealer. The malware executes a four-stage payload to exfiltrate browser credentials, session cookies, cryptocurrency wallet data, and sensitive local files. This sophisticated approach bypasses traditional static analysis and EDR via supply chain compromise and steganographic evasion, posing a severe risk to technical workstations and developer environments.

  • Threat Campaign: Contagious Interview

    • Targets software developers using social engineering via fake job offers and technical coding assessments.
    • Distributes malicious "coding tests" through fraudulent project repositories to trick victims into execution.
    • Attributed to state-sponsored North Korean actors focusing on high-value technical intelligence and developer workstations.
  • Attack Vectors: SVG Steganography and npm Supply Chain

    • Utilizes SVG steganography to hide executable data within graphic files, such as flag images, to evade EDR and static scanners.
    • Employs npm supply chain attacks using a two-layer dependency nesting strategy to bury the malicious payload.
    • Triggers payload extraction and subsequent execution once the developer initializes the project or installs dependencies.
  • Technical Execution: Four-Stage Payload Chain

    • Implements a four-stage execution sequence to move from initial package installation to full system compromise.
    • Employs advanced obfuscation techniques within the npm dependency chain to hinder reverse engineering and automated detection.
    • Establishes communication with external Command and Control (C2) infrastructure for data exfiltration.
  • Malware Capabilities: OtterCookie Data Exfiltration

    • Functions as a potent infostealer designed for targeted extraction of browser-stored credentials and session cookies.
    • Specifically scans for and exfiltrates private keys, seeds, and sensitive data from cryptocurrency wallets.
    • Conducts broad scans of the local file system to identify and steal sensitive documents and configuration files.
  • Defensive Actions and Mitigation

    • Implement rigorous auditing of npm dependencies, focusing on deep-nesting patterns and unverified maintainers.
    • Deploy advanced file analysis tools capable of detecting anomalous data blocks or embedded scripts within SVG files.
    • Enforce the use of isolated virtual environments (sandboxes) when evaluating third-party recruitment code or external repositories.

Related posts

  1. feeds.feedburner.com — Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
  2. malware-log.hatenablog.com — North Korea Buried Four-Stage Malware in Flag Images: Zero Antivirus Detections
  3. gbhackers.com — North Korean Contagious Interview Campaign Hides OTTERCOOKIE Malware in SVG Images
  4. Malware News — Amazon uncovers broad North Korean hacking campaign against open-source software
  5. serisec.com — Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
  6. The Record by Recorded Future — North Korean hackers behind major open-source supply chain attacks, Amazon says
  7. falconinternet.net — One Phished Maintainer, Four Poisoned Packages: Amazon Names North Korea in npm Supply Chain Campaign
  8. eSecurity Planet — Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
  9. computerweekly.com — Amazon pins multiple open source compromises on North Korea
  10. bleepingcomputer.com — Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
  11. Microsoft
  12. Darkreading
  13. Elastic
  14. Blog
  15. Medium
  16. Reddit
  17. Panther
  18. Stairwell
  19. Socdefenders
  20. Cybersecuritynews
  21. Kudelskisecurity
  22. Unit42
  23. Cyberpress
  24. Agentbreach
  25. About
  26. Pentagondesign
  27. cyberscoop.com — A little-known npm package was North Korea’s warm-up act for the axios hack
  28. Aws
  29. Seceon
  30. Youtube
  31. Neworleanscitybusiness
  32. Medium
  33. Esecurityplanet
  34. Reddit
  35. Nextgov
  36. Safedep
  37. Thehackernews
  38. Interlynk
  39. Reddit
  40. Aiweekly
  41. Infosecurity-magazine
  42. Secarma
  43. Utopiats
  44. Meritalk

LINK COPIED TO CLIPBOARD