
Key Summary
- According to a joint cybersecurity advisory, the Contagious Interview campaign has infected at least 30,000 devices across more than 100 countries
- Funds or account credentials were exfiltrated from more than 7,000 crypto wallets, with reported damages of approximately $10.71 million (USD 10.71M)
- The primary targets identified were individual-level freelancers and professionals, including web designers, engineers, and crypto experts
This article examines, from a threat intelligence perspective, the impact of North Korean targeted threats—exemplified by the fake job interview format—on developers and crypto users, and presents immediately deployable detection and response procedures for practitioners
Table of Contents
The ‘Contagious Interview’ campaign, disguised as fake job recruitment, swallowed 30,000 laptops and 7,000 crypto wallets in a single sweep. A joint cybersecurity advisory laid bare the full scale of the damage: more than 100 countries, at least $10.71 million.
The operation, which began in mid-2024, was classified as ‘WaterPlum.’ Web designers, blockchain engineers, and freelance developers were the primary targets. Under the guise of a coding test during the interview stage, victims were tricked into installing malicious npm packages. The PEEP backdoor, disguised as a browser extension, then siphoned off seed phrases and session cookies.
What I find most significant about this incident is the ‘industrialization’ of the fake job interview scam. A single infection is enough to drain wallet seeds, GitHub tokens, and cloud keys at once. Developers serve as the external touchpoint for small organizations, making them high-value targets.
Why the Fake Job Interview Scam Targeted Developers
From the attacker’s perspective, developers are a goldmine. They are likely to hold main account privileges, access to build pipelines, and internal repository keys. As remote interviews have become commonplace, actions that would normally raise suspicion—such as ‘screen sharing,’ ‘downloading files for a test,’ or ‘installing browser extensions’—have become natural within a hiring context.
The actual compromise flow is as follows. The attacker initiates contact through a fake job interview message and schedules an interview, then hands over a ‘technical assessment’ repository. One of the dependencies is the PEEP backdoor. The moment it is installed, MetaMask seeds, GitHub tokens, and cloud credentials are transmitted to an external C2 server.
| Stage | Action | Exfiltrated Data |
|---|---|---|
| 1. Initial Contact | Fake job interview outreach via LinkedIn and Telegram | — |
| 2. Infiltration | Coding test repository delivered; tricked into installing npm package | Execution privileges |
| 3. Collection | PEEP backdoor deployed as a browser extension | Session cookies, wallet seeds |
| 4. Exfiltration | Credential rotation, cloud key exfiltration | GitHub and AWS tokens |
Practical Application Points
Practical Application Points
The moment interview tools and assets coexist on the same device, you become the primary target of the fake job interview scam. Separating these two is the first gatekeeper.
- Use a separate device for interviews. Never take coding tests on a device that holds company assets or your main wallet. Conduct them only on a clean virtual machine or with a disposable account.
- Clone external repositories in an isolated environment. Run static analysis and SBOM checks before npm install. Even familiar package names can be tampered with.
What to Do Right Now
- Separate your interview GitHub account from your primary work account, and revoke all tokens once the interview is over.
- Move the seed phrase of your main crypto wallet to an offline paper backup, and store it separately from the hot wallet used for daily transactions.
- Enable hardware security key-based multi-factor authentication on major accounts such as GitHub, AWS, and Vercel, and rotate access keys every 30 days.
- If an interviewer requests ‘recording’ or ‘screen sharing,’ treat it as a red flag on the spot and verify the legitimacy through a separate channel with the hiring manager.
- When installing npm dependencies, make
npm auditand the--ignore-scriptsoption your default.
The Fake Job Interview Scam Never Ends
The terrifying thing about the fake job interview scam is that there is no ‘end.’ Once a seed phrase is exposed, attackers can trace every wallet address derived from that same seed. The seed that flows into a MetaMask extension is, in itself, a transaction signing key.
In my view, the real insight this campaign reveals is that the boundary of security responsibility has shifted to the individual endpoint. No matter how thoroughly an organization deploys SSO and EDR, a single developer’s laptop with a sticky note containing a seed phrase is enough to compromise the whole system.
Frequently Asked Questions
What channels do fake job interview scams use to make contact?
LinkedIn DMs and Telegram messenger are the most common. Recently, Telegram-based ‘technical assessment’ DMs have surged sharply. The Hacker News’s initial report also highlighted this channel expansion.
What are the red flags during the interview stage?
A typical pattern is when a coding test repository is sent at the last moment and results are demanded right after npm install. Abnormally high urgency, or restricting contact to Telegram only, are also warning signs.
What should I do if I’ve already installed the npm package?
Immediately disconnect from the internet and move funds from your main wallet to a cold wallet with a new seed. Then, from a separate device, invalidate session cookies and reissue all cloud keys.
Is a hardware wallet safe?
It is relatively safe if the seed phrase has never entered your PC. However, browser-side channels like the PEEP backdoor can intercept the transaction signing itself, so you must always verify the amount and recipient address on the device display right before signing.
Stage-by-Stage Hiring Security to Block the Fake Job Interview Scam
To block the fake job interview scam, security gates must be formalized at every stage of hiring. The starting point is breaking the assumption that ‘interview = zone of trust.’
| Hiring Stage | Current Practice | Improved Approach |
|---|---|---|
| Initial Contact | Free communication via email and messenger | Use only company domain email; reject Telegram policy |
| Technical Assessment | Candidate’s personal repository used | Assessments only in internal sandbox; repository whitelisting |
| Final Interview | Unrestricted screen sharing | Demonstrations only on interviewer’s device; advance notice of recording policy |
| Post-Hire | SSO issued immediately | 90-day least-privilege; regular key rotation |
100 countries, 30,000 devices, $10.71 million. The fake job interview scam is no longer something that can be stopped by ‘individual caution’ alone. Embedding security into the hiring process and ensuring that interviews and assets never coexist on the same device is the first line of defense.
If you want to dive deeper into the technical flow, we recommend reading the 8-month WaterPlum attack timeline and how the PEEP backdoor works.
Reference Sources
This article was written with reference to the following source: The Hacker News — Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
Expert Commentary (AI)
Cybersecurity Expert
The target is the individual developer, but the actual damage spreads through supply chain and cloud credentials—an industrialized social engineering threat
The greatest power of this campaign, which weaponizes fake job recruitment, lies in how a legitimate context such as hiring makes high-risk actions like screen sharing, file downloads, and extension installations feel natural. Given the nature of the npm ecosystem, the structure that allows arbitrary code to execute at the point of dependency installation is a fundamental, unresolved design weakness, and this campaign hit that weakness with precision. The way a browser-extension backdoor exfiltrates session cookies and seed phrases also leaves hardware wallet users exposed to signature interception risks, making it clear that individual-level defenses alone are insufficient. At the organizational level, embedding security gates directly into the hiring process is a sound approach, but to cover freelancers and external collaborators, industry-standard guidelines and accountability discussions involving platform providers (LinkedIn, npm, GitHub) must follow. Similar future campaigns are likely to expand into AI interview agents or automated coding assessment platforms, requiring a continuous supply-chain verification framework as a prerequisite.
Crypto Asset Security Expert
In a structure where seed phrase exposure leads directly to the complete loss of assets, a fundamental redesign of key management practices is urgently needed
The lesson this campaign leaves for the crypto ecosystem is clear: the moment a browser wallet seed phrase like MetaMask’s resides on a development PC, the assets at all addresses derived from that seed are collectively exposed to risk. The fact that derived address tracing is performed means a single exposure contaminates the entire historical record; simply moving funds is an insufficient response, and a complete transition to a new seed system is required. Functional separation of hot and cold wallets, and on-device signature verification with hardware wallets, are already proven best practices, but the scale of this damage shows these practices have not been widely adopted. However, a structure that places all responsibility on the individual has its limits, and product-level defenses—such as wallet manufacturers detecting malicious extensions, isolating seed input environments, and providing transaction simulation warnings—must become standard features. In the long term, a transition to passive keys or MPC-based signature structures will structurally neutralize this type of theft.
Critical Analyst
The 30,000-device tally released in a ‘joint advisory’ after 8 months of silence—the timing and the disclosing parties are what warrant suspicion first
Looking beneath the surface, there is no explanation for why the damage from an operation that began in mid-2024 was disclosed as a joint advisory only after more than 8 months. The $10.71 million figure is a number that, given the nature of the blockchain, can be largely verified through on-chain tracing, leaving open the possibility that authorities either missed it, or knew but chose the moment of disclosure. What we should really pay attention to is who benefits from such an advisory—vulnerability disclosures become the basis for product sales in the security industry, the North Korean threat exaggeration narrative becomes justification for cyber budget allocations, and the emphasis on crypto losses fuels regulatory tightening discourse. In a case where beneficiaries exist in all three directions, it is difficult to conclude that the disclosure was made solely for ‘victim protection.’ Ultimately, what readers must ask themselves is on whose tally basis, and for what purpose, this number has been disclosed now.
Behind-the-Scenes Scenarios
- Authorities and security firms may have identified the scale of infection much earlier but deliberately delayed disclosure to track threat actors and compile sanctions lists, releasing the findings timed with law enforcement actions—the fact that a precise tally of 30,000 devices across 100 countries could not have been compiled in a short period supports this.
- Platforms operating hiring services and the npm ecosystem, which have effectively overlooked review vulnerabilities, may be preparing to roll out their own security features before a massive damage disclosure shapes public opinion, and this advisory may be used as a prelude to that launch.
Leave a Reply