[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxBcSeMoNz65a6MnKWXulOXIK22uwsPXNq9s0RnhhQsI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"24878c3c-72d4-4000-bd4b-a052ebfd8a57","north-korean-actors-hide-malware-in-svg-images-targeting-developers-via-fake-job-tests","4ee400cb-f772-4ef9-a042-bcbec48059eb","North Korean Actors Hide Malware in SVG Images Targeting Developers via Fake Job Tests","The Contagious Interview campaign exploits developers' trust in legitimate hiring workflows by embedding OtterCookie malware within SVG flag images using steganography — a technique that hides malicious code inside innocent-looking files. By distributing these payloads through Slack job channels and fake coding challenges, attackers bypass traditional email-based defenses and prey on candidates eager to impress potential employers. The four-stage infection chain ultimately steals browser credentials, cryptocurrency wallets, and sensitive files, while establishing persistent remote access. This campaign demonstrates how social engineering through professional contexts (job hunting, coding tests) can be just as dangerous as phishing emails, particularly when targeting high-value technical staff who may feel a false sense of security on developer-centric platforms.","**Immediate actions:**\n- Warn all software developers and technical staff about fake coding challenge lures distributed via Slack, LinkedIn, and job boards, with specific emphasis on SVG and archive file risks.\n- Block or sandbox the execution of unsolicited code repositories, scripts, or challenge files received through non-corporate channels before they run on any company-connected device.\n\n**Long-term improvements:**\n- Implement a verified, isolated sandbox environment (e.g., a dedicated VM or container) for evaluating any externally sourced code as a mandatory policy for all technical employees.\n- Establish a supply chain and third-party vetting policy that includes scrutiny of recruiting platforms and external communication channels like Slack workspaces.\n- Deploy endpoint detection and response (EDR) solutions capable of identifying steganographic payload extraction and multi-stage dropper behavior.\n\n**Detection measures:**\n- Enable deep content inspection and file-type analysis on all inbound files, particularly SVG, ZIP, and archive formats, to detect embedded payloads.\n- Monitor for anomalous processes spawned from developer tools (Node.js, npm, Python) that attempt to access browser credential stores, crypto wallet directories, or initiate outbound connections.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 3: Data Protection","CIS Control 9: Email and Web Browser Protections","CIS Control 14: Security Awareness and Skills Training","NIST SP 800-53 AT-2: Security Awareness Training","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 SA-12: Supply Chain Protection","NIST CSF DE.CM-4: Malicious Code Detection","MITRE ATT&CK T1566: Phishing (Spearphishing via Service)","MITRE ATT&CK T1027.003: Steganography","MITRE ATT&CK T1195: Supply Chain Compromise","GDPR Article 32: Security of Processing (credential\u002Fdata theft implications)","published","2026-07-17T16:21:38.142785+00:00","2026-07-17T16:21:37.847+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fnorth-korea-linked-hackers-hide.html","fake-coding-tests-deliver-ottercookie-aligned-malware-hidden-in-svg-flag-images-7dc987","Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":38,"name":39,"slug":40,"description":41,"color":42},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]