HomeSecurityContagious Interview - North Korea: 1,700 malicious npm, PyPI, Go, Rust packages

Contagious Interview – North Korea: 1,700 malicious npm, PyPI, Go, Rust packages

The North Korean -linked Contagious Interview operation has spread over 1,700 malicious packages to popular software repositories, targeting the npm , PyPI , Go , Rust , and PHP ecosystems. Socket researchers discovered that these packages were designed to mimic legitimate developer tools while also acting as malware loaders in a coordinated supply chain attack.

Contagious Interview - North Korea: 1,700 malicious npm, PyPI, Go, Rust packages

According to security researcher Kirill Boychenko of Socket, this campaign represents a significant evolution in the tactics of North Korean hackers. The malicious packages include:

  • npm: dev-log-core, logger-base, logkitx, pino-debugger, debug-fmt, debug-glitz
  • PyPI: logutilkit, apachelicense, fluxhttp, license-utils-kit
  • Go: github[.]com/golangorg/formstash, github[.]com/aokisasakidev/mit-license-pkg
  • Rust: logtrace
  • Packagist: golangorg/logkit

The strategic choice of these names is not accidental – they mimic popular logging and debugging tools widely used by developers worldwide.

See also: Contagious Interview: Attack with 338 malicious npm packages

The technique used by the attackers is highly sophisticated and demonstrates a deep understanding of software development practices. Rather than activating the malicious code during installation, they embed it in seemingly legitimate functions that match the advertised purpose of the package. For example, in the case of logtrace, the code is hidden within the Logger::trace(i32), which would not arouse suspicion to a programmer performing routine debugging tasks. This approach makes detection extremely difficult, as the malware is only activated when specific functions are called during normal use of the software.

Contagious Interview - North Korea: 1,700 malicious npm, PyPI, Go, Rust packages

Technical details of the Contagious Interview attack

Malware loaders are designed to retrieve second-stage payloads, depending on the platform, which are pieces of malware with infostealer and remote access trojan (RAT). These tools mainly focus on collecting data from web browsers, password managers, and cryptocurrency wallets. The Windows of the malware (delivered via the license-utils-kit) incorporates a full post-compromise implant that acts as a complete cyberespionage.

This implant has extensive capabilities, including executing shell, logging keystrokes, stealing data from browsers, uploading files, terminating web browsers, deploying AnyDesk for remote access, creating encrypted files, and downloading additional modules.

See also: Contagious Interview: The technique of North Korea's fake IT workers

Socket describes this group as notable not only for targeting multiple ecosystems, but also for its post-breach activities. The malware's ability to remain dormant for extended periods makes it particularly dangerous for long-term espionage operations.

The expansion of the Contagious Interview to five open source ecosystems suggests that this is a well-funded and persistent threat to the supply chain. Attackers have planned to infiltrate these platforms to compromise developer environments for espionage and financial gain.

Contagious Interview - North Korea: 1,700 malicious npm, PyPI, Go, Rust packages

Connection with other North Korean hacker operations

This discovery is part of a broader campaign of software supply chain breaches by North Korean hacking groups. One of the most recent attacks is on the popular npm package Axios to distribute an implant called WAVESHAPER.V2.

The attack has been attributed to a financially motivated threat actor known as UNC1069, which overlaps with the BlueNoroff, Sapphire Sleet , and Stardust Chollima. The Security Alliance (SEAL) said it blocked 164 domains associated with UNC1069 that mimicked services such as Microsoft Teams and Zoom.

See also: Hackers target developers with 35 malicious npm packages

Practical security tips for developers

To protect against such attacks, developers and organizations must adopt a multi-layered security approach. First, it is critical to use scanning tools dependency to continuously monitor the supply chain. Second, they should verify the origin of packages, check recent changes and download statistics, and favor locked versions. Third, running tasks in isolated environments such as sandboxes or virtual machines can limit the impact of an attack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS