1、Hunting North Koreas State-Sponsored“Contagious Interview”Operation:Attacks on Developers via the Software Supply ChainAdversarial tradecraft:How threat actors weaponize open source.Social engineering:Recruiter lures targeting developers and job seekers.Malware zoo:First,second,and third-stage paylo
2、ads.Threat hunting:Detection and triage.Defense guidance:Identify and mitigate risk.Memes:Just a few.From North Korea(DPRK)to the U.S.and BackInterview?Yes,its fake recruiter outreach and an interview-like scenario.Contagious?The“assignment”gets targets to run code thats actually malware.How long ha
3、s it been around?First malicious infrastructure detected in 2022.Really North Korea?High-confidence by USG,and leading security companies.Scale of intrusions?Thousands of victims and infected systems.Scale of theft?North Koreas overall crypto theft$2.02B in 2025 but no vetted total just for Contagio
4、us Interview operation.Contagious Interview What,Why,WhowhoamiKirill Boychenko Senior Threat Intelligence Analyst at Socket(software supply chain security company).Now:Hunt threats,reverse malware,and track adversarial activity across a dozen ecosystems.Previously:CTI and malware analysis at Recorde
5、d Futures Insikt Group(ARMOR:Advanced Reversing,Malware,Operations,and Reconnaissance).SANS Technology Institute alumInfiltrating Official Package RegistriesInfiltrating Official Package RegistriesModern Software Is Composed,Not Written From ScratchOpen Source Dependencies Create a Software Supply C
6、hainModern application has 70 90%open source components(direct and transitive dependencies).GitHub hosts 400M+code repositories and 100M+developers.Open source ecosystems like npm for Node.js(JavaScript/TypeScript)and PyPI for Python have millions of packages with billions of downloads.Open Source S