Find notable cyber news and cases, enriched with sources, timelines, and signals.

PurpleBravo Contagious Interview campaign

Campaign
First reported
Last updated
Happening score
H score 49
3 unique sources, 5 articles

Summary

Hide ▲

The North Korea-linked Contagious Interview operation, also tracked as PurpleBravo, has evolved from fake-job lures into a broader malware and supply-chain campaign. Recorded Future linked it to 3,136 IP addresses and 20 potential victim organizations across AI, cryptocurrency, financial services, IT services, marketing, and software development in Europe, South Asia, the Middle East, and Central America, with activity assessed from August 2024 to September 2025 and tooling including LinkedIn personas, malicious VS Code projects, malicious GitHub repositories, BeaverTail, GolangGhost, and Astrill VPN-run C2. Later reporting added AkdoorTea, TsunamiKit, and Tropidoor against developers, then Trend Micro said Void Dokkaebi/Famous Chollima turned the operation into a self-propagating repository and VS Code threat. Cisco Talos subsequently reported BeaverTail/OtterCookie convergence, OtterCookie v5 keylogging and screenshotting, EtherHiding delivery, and a Sri Lanka-headquartered victim infected through Chessfi.

Related Happenings

Shai-Hulud worm clone activity on NPM

Malware Activity
H score69 First: 18.05.2026 12:45 Last: 18.05.2026 12:45 Sources 1

About this happening: The Shai-Hulud malware activity has continued to evolve across the npm supply chain and related developer ecosystems. It first infected npm packages in September 202...

Shai-Hulud supply-chain campaign spreading via stolen CI/CD credentials

Campaign
H score56 First: 12.05.2026 14:29 Last: 12.05.2026 14:29 Sources 1

About this happening: GitHub said it removed more than 500 compromised npm packages in September 2025 and moved to harden publishing after early Shai-Hulud activity. In May 2026, researcher...

Mini Shai-Hulud npm supply-chain malware wave

Malware Activity
H score68 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The Mini Shai-Hulud npm malware activity now includes the Miasma variant affecting Microsoft GitHub repositories in a self-replicating supply-chain campaign. O...

Latest development: 09.06.2026 18:42

On June 5, Microsoft removed 73 repositories across its Azure, microsoft, Azure-Samples, and MicrosoftDocs organizations on GitHub after concerns about potential malicious content tied to the Miasma/Shai-Hulud supply-chain campaign. The action disrupted continuous integration pipelines and broke workflows that depended on Azure/functions-action, while Microsoft said it temporarily removed some repositories during its investigation.

TeamPCP Mini Shai-Hulud npm supply-chain campaign

Campaign
H score75 First: 12.05.2026 14:07 Last: 12.05.2026 14:07 Sources 1

About this happening: The TeamPCP-linked Mini Shai-Hulud campaign is an active npm supply-chain operation that steals developer credentials and abuses trusted publishing paths to spread tro...

TrickMo C TikTok-lure campaign targeting banking and wallet users in France, Italy, and Austria

Campaign
H score33 First: 11.05.2026 18:15 Last: 11.05.2026 18:15 Sources 1

About this happening: The TrickMo operators ran an active TikTok-themed campaign between January and February 2026, targeting banking and wallet users in France, Italy and Austria....

Timeline

  1. 22.04.2026 17:48 2 articles · 2mo ago

    Void Dokkaebi turns Contagious Interview into a self-propagating supply chain campaign

    Campaign Scope Update

    North Korean actor Void Dokkaebi, aka Famous Chollima, pushed the Contagious Interview fake-job campaign into a self-propagating software supply chain operation by abusing compromised developer repositories, malicious Visual Studio (VS) Code tasks, and injected code that can run during normal development activity to spread malware and steal cryptocurrency wallet credentials, signing keys, and access to CI/CD pipelines and production infrastructure. Trend Micro said the campaign also stages payloads on Tron, Aptos, and Binance Smart Chain, and in March it found more than 750 infected code repositories, more than 500 malicious VS Code task configurations, and 101 instances of the commit-tampering tool.

    Show sources
  2. 21.01.2026 19:17 2 articles · 5mo ago

    PurpleBravo disclosure of targeted interview campaign

    Initial Disclosure

    Recorded Future's Insikt Group disclosed new findings on PurpleBravo, a North Korean threat cluster also tracked as Contagious Interview, linking 3,136 IP addresses to likely targets and identifying 20 potential victim organizations across artificial intelligence (AI), cryptocurrency, financial services, IT services, marketing, and software development in Europe, South Asia, the Middle East, and Central America. The activity was assessed to have targeted IP addresses from August 2024 to September 2025 and used fake job offers, LinkedIn personas, malicious Microsoft Visual Studio Code (VS Code) projects, malicious GitHub repositories, BeaverTail, GolangGhost, and Astrill VPN-administered C2 infrastructure.

    Show sources
  3. 25.09.2025 16:14 2 articles · 9mo ago

    Contagious Interview deploys AkdoorTea against software developers

    Technical Analysis Update

    ESET said the North Korea-linked Contagious Interview campaign, also tracked as DeceptiveDevelopment, is targeting software developers across Windows, Linux and macOS, especially those working on cryptocurrency and Web3 projects, by using fake recruiter outreach on LinkedIn, Upwork, Freelancer and Crypto Jobs List and luring targets into video-assessment or coding workflows that deliver AkdoorTea, TsunamiKit, Tropidoor and other malware.

    Show sources