Contagious Interview npm malicious package campaign
Campaign
Summary
Hide ▲
Show ▼
The Contagious Interview campaign expanded with 197 more malicious npm packages, extending a supply-chain delivery route that targets npm users and developers. The packages were downloaded over 31,000 times, increasing the chance of victim exposure at scale. They deliver an updated OtterCookie payload that can establish C2 and steal credentials, screenshots, and crypto wallet data.
Related Happenings
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware Activity
H score30
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware ActivityAbout this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
Lucide proxy npm packages browser DDoS botnet
Malware Activity
H score31
First: 14.07.2026 10:08
Last: 14.07.2026 10:08
Sources 1
About this happening:
A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Lucide proxy npm packages browser DDoS botnet
Malware ActivityAbout this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
TonRAT Node.js implant with TON blockchain C2
Malware Activity
H score24
First: 26.06.2026 12:27
Last: 26.06.2026 12:27
Sources 1
About this happening:
TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
TonRAT Node.js implant with TON blockchain C2
Malware ActivityAbout this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
Campaign
H score9
First: 23.06.2026 11:54
Last: 23.06.2026 11:54
Sources 1
About this happening:
A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
CampaignAbout this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
AUR package-hijacking campaign delivering atomic-lockfile
Campaign
H score11
First: 12.06.2026 20:03
Last: 12.06.2026 20:03
Sources 1
About this happening:
AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...
AUR package-hijacking campaign delivering atomic-lockfile
CampaignAbout this happening: AUR package-hijacking campaign is abusing more than 400 compromised Arch User Repository (AUR) packages to deliver atomic-lockfile, turning the AUR build path...
Timeline
-
28.11.2025 18:18 2 articles · 7mo ago
Contagious Interview adds 197 malicious npm packages
Campaign Scope UpdateNorth Korean threat actors expanded the Contagious Interview campaign by flooding the npm registry with 197 more malicious packages, which Socket says were downloaded over 31,000 times. The packages are designed to deliver an updated OtterCookie payload that blends BeaverTail and prior OtterCookie features, connects to the hard-coded Vercel URL tetrismic.vercel[.]app, and then retrieves the payload from a threat actor-controlled GitHub repository; the delivery account stardev0914 is no longer accessible.
Show sources
- North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware — thehackernews.com — 28.11.2025 18:18
- North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malware — thehackernews.com — 28.11.2025 18:18