Contagious Interview UNK_DeadDrop GitHub phishing campaign
Campaign
Summary
Hide ▲
Show ▼
The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 organizations. The operation routes targets to actor-controlled GitHub repositories and VS Code projects that can trigger malicious code with little interaction. The campaign spans finance, cryptocurrency, education, technology, and other sectors, raising the risk of malware execution and credential theft.
Related Happenings
GitHub API enumeration campaign targeting corporate organizations
Campaign
H score17
First: 09.07.2026 21:38
Last: 09.07.2026 21:38
Sources 1
About this happening:
A GitHub API reconnaissance campaign is systematically mapping corporate organizations, repositories, and user accounts across multiple companies, expanding the risk of fo...
GitHub API enumeration campaign targeting corporate organizations
CampaignAbout this happening: A GitHub API reconnaissance campaign is systematically mapping corporate organizations, repositories, and user accounts across multiple companies, expanding the risk of fo...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
Campaign
H score9
First: 23.06.2026 11:54
Last: 23.06.2026 11:54
Sources 1
About this happening:
A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
CampaignAbout this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
Ghost Networks crypto-clipper promotion campaign
Campaign
H score15
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Ghost Networks crypto-clipper promotion campaign
CampaignAbout this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
JetBrains Marketplace malicious plugins exfiltrating AI provider keys
Malware Activity
H score12
First: 17.06.2026 12:38
Last: 17.06.2026 12:38
Sources 1
About this happening:
A JetBrains Marketplace malware operation has pushed 15 malicious plugins that pose as AI coding assistants and steal AI provider API keys from developers. The plugins...
JetBrains Marketplace malicious plugins exfiltrating AI provider keys
Malware ActivityAbout this happening: A JetBrains Marketplace malware operation has pushed 15 malicious plugins that pose as AI coding assistants and steal AI provider API keys from developers. The plugins...
Timeline
-
15.06.2026 22:32 2 articles · 1mo ago
Researchers identify UNK_DeadDrop phishing campaign targeting developers
Initial DisclosureResearchers tracked UNK_DeadDrop, a campaign linked to Contagious Interview, that targeted nearly 100 organizations in finance, cryptocurrency, education, technology, and other sectors with developer recruitment and code review lures. Recipients were directed to actor-controlled GitHub repositories and VS Code projects that used the runOn: folderOpen technique to execute malicious code, deploy cross-platform loaders for macOS, Linux, and Windows, and support credential and wallet theft through Overlord-related tooling.
Show sources
- North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels — thehackernews.com — 15.06.2026 22:32
- North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels — thehackernews.com — 15.06.2026 22:32