Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
- ID
- 26957
- Status
- summarized
- Published
- 22 Sep 2026, 1:19 AM
- Fetched
- 22 Sep 2026, 3:24 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/contagious-interview-campaign.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 5.5
- Created
- 22 Sep 2026, 3:28 AM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
A joint advisory from Japan, U.S., Australia, and Germany reports that North Korean threat actors behind the 'Contagious Interview' campaign have compromised 30,000+ devices across 100+ countries since at least 2022, stealing $10.71M from 7,000+ crypto wallets. The attackers pose as recruiters on LinkedIn, lure developers and Web3 specialists into fake coding assessments, and deploy malware families like BeaverTail, InvisibleFerret, and OtterCookie via the infection chain.
Why it matters
If you or your team members are job hunting or taking coding tests from unfamiliar recruiters—especially those contacting via LinkedIn with crypto/Web3 roles—treat unsolicited coding assessments as untrusted code execution. Running interview take-homes or test projects in isolated VMs rather than your primary dev machine is now a baseline precaution, not paranoia.
Discussion angle
How do you safely evaluate coding tests from unknown employers without running potentially malicious code on your machine—practical sandboxing setups for job seekers in the current market?