North Korea’s Contagious Interview Campaign Escalates: 338 Malicious npm Packages, 50,000 Downloads
Blog post from Socket
The Contagious Interview operation involves North Korean threat actors systematically exploiting the npm registry through a sophisticated and ongoing campaign. Since mid-2025, they have introduced over 338 malicious packages, with a significant portion still active, targeting Web3, cryptocurrency, and blockchain developers, as well as job seekers. These threat actors use fake recruiter personas on platforms like LinkedIn to lure targets into downloading and executing malicious software disguised as legitimate npm packages. Their tactics include typosquatting popular package names, evolving malware loaders, and leveraging social engineering to compromise systems, leading to financial theft and espionage. Despite takedown efforts, the attackers adapt rapidly, maintaining active accounts to continue their operations. The campaign underscores the need for enhanced security measures in software supply chains, including robust account verification, pre-publish screenings, and real-time scanning of code and pull requests to mitigate such persistent threats.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 2 | 6,551 | 1,245 | 236 | +61% |
| LLM | 1 | 4,863 | 783 | 205 | +34% |
| MCP | 1 | 4,861 | 352 | 133 | +57% |
| Secrets Management | 1 | 1,168 | 199 | 91 | +15% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.