LW21: Developer execution, in-memory access, and bridge compromise
Executive Summary
Developer compromise dominated last week’s reporting. Fake interviews, poisoned repositories, npm install hooks, editor automation, compiled malware, and trojanized browser extensions all targeted workstations that already held source-control, cloud, package, and wallet credentials. New reporting on Axios-related infrastructure and packages widened that picture beyond a single compromise.
RemotePE and the KelpDAO investigation showed the other end of the access chain: quiet persistence inside financial environments and manipulation of bridge verification infrastructure. Reporting on IT workers, sanctions, and operator forensics connected technical intrusion to identity fraud, laundering, and revenue generation, while two adjacent financial-sector reports required more cautious attribution.
Key Trends
1. Fake interviews turned normal developer actions into execution
A developer safety analysis described the core lure plainly: clone a repository, install dependencies, open it in an editor, or run a test on a workstation that already contains valuable credentials.1 GitHub network analysis found Contagious Interview repositories abusing VS Code and Cursor configuration, git hooks, npm lifecycle scripts, and hidden JavaScript, with newer BeaverTail builds adding operator-directed WebSocket control.2
Trend Micro found InvisibleFerret moving into Cython-compiled Windows and macOS modules, complicating script-focused detection while preserving browser, wallet, clipboard, and keylogging functions.3 The progression from social engineering to compiled payloads and persistent control makes isolated repository review an incomplete defense.
2. npm and browser components collected developer and wallet secrets
A cross-platform Node.js stealer tied to an OtterCookie C2 targeted browser credentials, wallet data, private keys, tokens, SSH keys, and source code on Windows, macOS, and Linux.4 OX Security found similar breadth in terminal-logger-utils, which used a postinstall hook, bundled Node executables, Hugging Face, and WebSocket remote control.5
Three npm packages linked to the Axios attacker had collected developer, cloud, npm, SSH, Docker, browser, and git data for weeks.6 OpenSourceMalware placed those packages within parallel Contagious Interview and TasksJacker activity,7 while DNS analysis of the Axios operation mapped the confirmed WAVESHAPER.V2 infrastructure and separated it from unverified pivots.8
The browser layer was also exposed. Five trojanized extensions masqueraded as password managers or wallets, resolved C2 through an Aptos transaction, and linked stolen wallet artifacts to browser identity data.9
3. Financial intrusions favored durable, low-noise access
Fox-IT described RemotePE as an in-memory RAT delivered through victim-bound DPAPI decryption and a loader that unhooked DLLs, patched ETW, and resolved direct syscalls.10 The KelpDAO incident report then documented social engineering against a LayerZero developer, session-key theft, poisoned RPC nodes, monitoring evasion, and a single-verifier design that accepted the attacker’s attestation.11
Chainalysis connected DPRK IT worker proceeds and cyber theft to exchanges, bridges, DeFi services, and mixers used for sanctions evasion.12 These reports join endpoint access, cloud sessions, bridge verification, and laundering into one defensive problem.
4. IT worker and operator evidence exposed the human infrastructure
A suspected Chollima applicant used a Colombian identity and a residential Bogota connection, possibly through local facilitation or a residential proxy, while showing behavior consistent with AI-assisted interviewing.13 A forensic episode about a Lazarus-attributed operator disk described fake-company material, targeting pipelines, wallet artifacts, and browser traces from an eleven-hour preservation window.14
A broader campaign-linkage assessment argued that IT worker fraud, recruitment lures, cloud compromise, credential theft, and cryptocurrency operations share access and infrastructure.15 That assessment is useful as a model, but the incident-level evidence should still determine attribution in each case.
5. Financial-sector overlap did not always establish attribution
AhnLab linked observed WGear exploitation and GeniexLoader installation to activity associated with Andariel and BlueNoroff.16 Its Endpoint/Midnight ransomware analysis, however, found only that a historical ransom-note email had been used by a North Korea-linked actor; it did not attribute the ransomware family itself.17
Bridewell’s annual report supplied broader context on identity compromise, trusted-platform abuse, supply chain attacks, and attacker use of AI.18 These trend-level and adjacent findings belong below directly attributed cases in analytic confidence.
What to Watch
Inspect interview repositories before they reach a normal workstation. Block automatic folder tasks and install hooks in untrusted projects, and review browser extensions, package tokens, SSH agents, cloud credentials, and wallet access after any suspected execution. In financial environments, correlate those endpoint signals with unusual RPC changes, session-key use, and verifier behavior.
Reports Reviewed
A Fake Coding Interview Is an Execution Request: Developer Safety Checklist ↩︎
Deep Dive into Active Github Network Running Contagious Interview ↩︎
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware ↩︎
North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT ↩︎
Axios attacker strikes again! Three NPM packages have been hiding in plain sight for two months ↩︎
OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses ↩︎
Eleven Hours: Inside the Lazarus Operator’s Disk After the Fake Interview Campaign ↩︎
Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis ↩︎