CuraSec

Act archived

NK Contagious Interview Uses SVG Steganography in Fake Coding Tests

2026-07-18 11:51 UTC · The Hacker News · read the source ↗ #north-korea#supply-chain#malware
  • Engineer — Learn: No patch exists for this social-engineering vector; awareness matters for dev teams who might receive unsolicited coding challenges or interview tasks containing SVG assets with hidden payloads.
  • SOC/IR — Act: Hunt for developer endpoints that recently cloned/ran unknown repositories, inspect for OtterCookie IOCs including browser credential and crypto wallet access patterns, and add detections for SVG files embedding executable content in CI/CD artifact pipelines.
  • Leader — Learn: This Contagious Interview campaign targets developers via fake job postings — relevant context for board-level awareness of North Korean IT worker and recruitment-lure threats, but no immediate leadership action required.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.