Contagious Interview malware in SVG images: DPRK campaign
Essential information
- Published
- 17/07/2026 22:08
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- beavertail cryptocurrency wallet theft developer targeting dprk fake job interviews ottercookie steganography supply chain attack svg
- Related entities
- 13 indicators, 4 observables, 1 intrusion sets (apt), 19 techniques (mitre), 2 malware
Description
A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.