Contagious Interview Campaign Escalates With 67 Malicious np...
Blog post from Socket
A recent escalation in the Contagious Interview campaign, linked to North Korean threat actors, has been identified by the Socket Threat Research Team, involving the deployment of 67 malicious npm packages using the newly discovered XORIndex malware loader. This campaign continues the activities from June 2025, where the HexEval Loader was initially reported, and involves infiltrating the npm ecosystem, with 27 packages still active and collectively downloaded over 17,000 times. The XORIndex Loader, characterized by its use of XOR-encoded strings and index-based obfuscation, functions alongside the HexEval Loader, with both operations focusing on software supply chain attacks targeting developers, job seekers, and individuals with cryptocurrency or sensitive credentials. XORIndex collects host metadata and executes second-stage malware, BeaverTail, which in turn references the third-stage InvisibleFerret backdoor. This campaign, leveraging legitimate infrastructure providers like Vercel, showcases a rapid evolution in malware tactics, with continued iterations and new obfuscation techniques posing challenges for detection and incident response efforts.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.