GitLab ’s investigation has uncovered the latest techniques behind fake North Korean IT worker scams. GitLab banned 131 accounts attributed to North Korea, most of which included JavaScript repositories that served as resources in the so-called Contagious Interview campaign. In most cases, GitLab projects acted as obfuscated loaders for malicious payloads — such as BeaverTail and Ottercookie — hosted outside the code repository platform.
See also: Lazarus subgroup uses Medusa ransomware

The Contagious Interview campaign revolves around North Korean threat actors posing as recruiters in order to trick software developers into executing malicious code projects under the guise of technical interviews. The operators typically used consumer VPNs when interacting with GitLab, but some occasionally routed their access through dedicated virtual private server (VPS) infrastructures or laptop farms.
GitLab has been disrupting these operations by banning suspicious repositories. These suspicious code repositories were being misused in a variety of illegitimate projects that were split between targeting job-seeking developers and fake IT worker operations. “Based on our visibility, malware operations targeting individual job-seeking developers are the most common,” Oliver Smith, senior threat intelligence engineer at GitLab, told CSO.
For fake IT worker operations, threat actors typically find work in smaller organizations looking for contract software developers, particularly through freelance platforms. Larger organizations are also being targeted by the ongoing scams, which began in earnest in 2022 and have been going on since 2019.
See also: North Koreans pose as IT professionals on LinkedIn to infiltrate companies

The crooks’ technique evolved last year through the use of malicious NPM package manager components, sandbox detection, and an increasing reliance on private, invite-only projects. North Korean actors also relied more on AI technologies to develop custom obfuscations and through the automation of the creation of synthetic identities, created for professional connections and contacts at scale, GitLab explains in a technical blog post.
An IT worker was checking 21 unique personas, created by adding their own image to stolen scans of U.S. ID documents. Some of the banned repositories contained personal files, passport scans, bank records at multiple Chinese banks, and structured quarterly performance sheets.
GitLab explains how a repository reveals detailed financial and personal records for a possible Beijing-based cell of North Korean IT workers who earned more than $1.64 million between the first quarter of 2022 and the third quarter of 2025. The eight-person North Korean cell generated revenue through free web and mobile software development while pretending to be fake identities.
Profits fell last year, but were still more than $11,000 per member in the third quarter of 2025, according to their own records. The private project also contained performance reviews for the cell’s members, dated 2020.
See also: The rise of North Korean hackers: $2 billion in cryptocurrencies stolen

The North Korean fake IT worker scam is a cross-cutting issue. GitLab hopes its detailed research, which includes more than 600 breach indicators related to the case studies analyzed during its research, will help empower advocates across the industry.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
