Home / Companies / Socket / Blog / Post Details
Content Deep Dive

North Korea’s Contagious Interview Campaign Escalates: 338 Malicious npm Packages, 50,000 Downloads

Blog post from Socket

Post Details
Company
Date Published
Author
Kirill Boychenko
Word Count
3,160
Company Posts That Month
24
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Contagious Interview operation involves North Korean threat actors systematically exploiting the npm registry through a sophisticated and ongoing campaign. Since mid-2025, they have introduced over 338 malicious packages, with a significant portion still active, targeting Web3, cryptocurrency, and blockchain developers, as well as job seekers. These threat actors use fake recruiter personas on platforms like LinkedIn to lure targets into downloading and executing malicious software disguised as legitimate npm packages. Their tactics include typosquatting popular package names, evolving malware loaders, and leveraging social engineering to compromise systems, leading to financial theft and espionage. Despite takedown efforts, the attackers adapt rapidly, maintaining active accounts to continue their operations. The campaign underscores the need for enhanced security measures in software supply chains, including robust account verification, pre-publish screenings, and real-time scanning of code and pull requests to mitigate such persistent threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 2 6,551 1,245 236 +61%
LLM 1 4,863 783 205 +34%
MCP 1 4,861 352 133 +57%
Secrets Management 1 1,168 199 91 +15%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.