Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Contagious Interview malware in SVG images: DPRK campaign

0
Medium
Published: 07/17/2026 (07/17/2026, 20:08:00 UTC)
Source: AlienVault OTX General

Description

A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/18/2026, 11:11:58 UTC

Technical Analysis

The Contagious Interview campaign, attributed to a DPRK-aligned threat actor tracked as REF9403, targets developers by posting fake job offers and coding challenges on developer forums. The attackers provide trojanized repositories with fully functional e-commerce projects embedding malicious code concealed using steganography within SVG flag images. Upon running these projects, a four-stage malware payload aligned with OTTERCOOKIE is deployed, comprising a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was uncovered following attacks on Elastic's community Slack workspace. The malware's initial zero antivirus detection rate demonstrates a sophisticated supply chain attack method against software developers.

Potential Impact

The malware can steal browser credentials and cryptocurrency wallets, exfiltrate files, provide remote access to attackers, and steal clipboard data. This compromises developer systems, potentially leading to credential theft, financial loss, data leakage, and unauthorized remote control. The supply chain nature of the attack increases risk by targeting developers who may unknowingly distribute compromised code.

Defensive Guidance

No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Developers should exercise caution when accepting job offers or coding challenges from unverified sources and thoroughly vet any third-party repositories before use. Employing endpoint detection and response solutions capable of detecting steganography or multi-stage malware may help. Monitor for indicators of compromise such as the provided hashes and domains. Since this is not a cloud service, remediation depends on user vigilance and security controls.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography"]
Adversary
Contagious Interview
Pulse Id
6a5a8ba0229db5a5b2686baa
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3c
hash4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864
hash54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9
hash8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1e
hash96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20
hash9df01d242ef46adfedf8c35cb7cc67b1d27d7dc4a1ce74ab32e984090d579886
hashc5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9
hashcc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730
hashfb94b2caee2c40635448a98ba0118421e19a400e74ccff73315f8fa42351f53f

Domain

ValueDescriptionCopy
domaincontroller.rightwidth.dev
domainfile.rightwidth.dev
domainldb.rightwidth.dev
domainupload.rightwidth.dev

Threat ID: 6a5b3f7634329bf928c66a8f

Added to database: 07/18/2026, 08:55:18 UTC

Last enriched: 07/18/2026, 11:11:58 UTC

Last updated: 08/31/2026, 13:16:57 UTC

Views: 131

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses