• News/
  • https://www.bleepingcomputer.com/news/security/new-wave-of-fake-interviews-use-35-npm-packages-to-spread-malware/

New wave of ‘fake interviews’ use 35 npm packages to spread malware

BleepingComputer
·
Bill Toulas
·
Published Jun 25, 2025
·
Updated

A new wave of North Korea's 'Contagious Interview' campaign is targeting job seekers with malicious npm packages that infect dev's devices with infostealers and backdoors. The packages were discovered by Socket Threat Research, which reports they load the BeaverTail info-stealer and InvisibleFerret backdoor on victims' machines, two well-documented payloads associated with DPRK actors. The latest attack wave uses 35 malicious packages submitted to npm through 24 accounts. The packages have been downloaded over 4,000 times in total, and six of them remain available at the time of writing. Several of the 35 malicious npm packages typosquat or mimic well-known and trusted libraries, making them especially dangerous. Notable examples of those are: Victims, typically software engineers and developers, are led to download these packages by North Korean operatives posing as recruiters, requesting job candidates to work on a test project. "Posing as recruiters on LinkedIn, the North Korean threat actors send coding "assignments" to developers and job seekers via Google Docs, embed these malicious packages within the project, and often pressure candidates to run the code outside containerized environments while screen-sharing," explains Socket. The assignments are hosted on Bitbucket and disguised as legitimate tests, but in reality, they trigger an infection chain that drops multiple payloads on the target's computer. The first stage is HexEval Loader, hidden in the npm packages, wh...

Read full article

Affected Software

1 affected component
npm malicious package

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new wave of fake job interviews using 35 malicious npm packages to spread malware.

2

What security implications are discussed?

The security implications include the risk of infection from infostealers and backdoors on developers' devices.

3

What products or software are affected?

The affected software includes several malicious npm packages used to deliver malware.

4

Who is behind the malicious campaign mentioned in the article?

The campaign is attributed to North Korea's targeting of job seekers through deceptive tactics.

5

How are job seekers being targeted in this campaign?

Job seekers are being targeted through fake interviews that utilize malicious npm packages.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203