Executive Summary
Between December 2025 and July 2026, the North Korean hacking group WaterPlum executed a sophisticated supply chain attack through their "Contagious Interview" campaign, compromising over 30,000 devices across more than 100 countries. The attackers impersonated legitimate AI, cryptocurrency, and NFT companies to target job seekers with malicious npm packages and fake coding tests, ultimately stealing cryptocurrency credentials from over 7,000 wallets and transferring $10.7 million to North Korea. The operation combined social engineering with multiple malware families including BeaverTail, InvisibleFerret, and StoatWaffle to conduct financial theft and espionage.
This incident highlights the evolving sophistication of state-sponsored supply chain attacks that exploit trusted development environments and social engineering tactics, demonstrating how nation-state actors are increasingly targeting individual developers and IT professionals to fund weapons programs while simultaneously infiltrating corporate networks.
Why This Matters Now
Nation-state actors are increasingly weaponizing legitimate hiring processes and development tools to conduct supply chain attacks, making traditional perimeter defenses insufficient against sophisticated social engineering campaigns targeting remote workers and developers.
Attack Path Analysis
North Korean WaterPlum actors conducted a supply chain attack targeting IT professionals through fake job interviews and malicious npm packages, compromising 30,000+ devices across 100+ countries. Attackers used social engineering to deliver JavaScript and Python-based malware (BeaverTail, InvisibleFerret, OtterCookie), established persistent access through Visual Studio Code projects, and exfiltrated cryptocurrency credentials and sensitive data. The campaign resulted in theft of over $10.7 million in cryptocurrency transferred to North Korea, with attackers also pivoting to employer networks for intellectual property theft and espionage.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
WaterPlum actors impersonated legitimate AI/cryptocurrency companies on recruiting platforms, conducting fake interviews where victims were tricked into downloading malicious npm packages or Visual Studio Code projects containing JavaScript malware (BeaverTail) and Python backdoors (InvisibleFerret)
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
JavaScript
Credentials from Web Browsers
Keylogging
Screen Capture
Exfiltration Over C2 Channel
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Plan
Control ID: 12.10
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
DORA – Third-party Risk Management
Control ID: Article 11
CISA Zero Trust Maturity Model 2.0 – Software Platforms and Applications
Control ID: ID.AM-2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Information Security for Use of Cloud Services
Control ID: A.5.23
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
WaterPlum's supply chain attacks targeting IT professionals through malicious npm packages and fake interviews directly compromise IT infrastructure and development workflows.
Computer Software/Engineering
Software developers face direct targeting through compromised Visual Studio Code projects and malicious npm packages, enabling credential theft and lateral network movement.
Financial Services
Cryptocurrency wallet compromises affecting 7,000+ wallets with $10.7M stolen highlight critical risks to financial institutions handling digital assets and client credentials.
Staffing/Recruiting
Recruiting platforms exploited for fake interviews enable identity document theft for fraudulent IT worker operations, compromising hiring processes and client security.
Sources
- North Korean WaterPlum hackers infected 30,000 devices worldwidehttps://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/Verified
- Joint Cybersecurity Advisory: North Korean WaterPlum Threat Grouphttps://www.ic3.gov/CSA/2026/260918.pdfVerified
- North Korean WaterPlum Cyber Actor Group Alerthttps://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/north-korean-waterplum-commonly-referred-to-as-contagious-interview-cyber-actor-group-targeting-it-professionalsVerified
- North Korean WaterPlum hackers infected 30,000 devices worldwidehttps://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30,000-devices-worldwide/Verified
- Joint Cybersecurity Advisory - German Federal Office for the Protection of the Constitutionhttps://www.verfassungsschutz.de/SharedDocs/publikationen/DE/praevention_wirtschafts-und_wissenschaftsschutz/2026-09-18-joint-cybersecurity-advisory.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the WaterPlum campaign's lateral movement and data exfiltration capabilities through workload segmentation and controlled egress policies. The attack's blast radius across 30,000+ devices and employer networks could likely have been reduced through identity-aware access controls and east-west traffic enforcement.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise through social engineering may still have succeeded, but the malware's ability to communicate with command infrastructure would likely be constrained by default-deny egress policies and application-aware traffic inspection.
Control: Zero Trust Segmentation
Mitigation: Credential theft may have occurred locally, but the stolen authentication tokens would likely face restricted scope when attempting to access segmented cloud workloads and network resources beyond the immediate user context.
Control: East-West Traffic Security
Mitigation: Cross-network pivoting attempts would likely be significantly constrained through microsegmentation policies that inspect and control internal traffic flows between workloads, reducing the attackers' ability to expand their foothold across employer infrastructures.
Control: Multicloud Visibility & Control
Mitigation: Command and control communications would likely be constrained through comprehensive traffic visibility and policy enforcement across cloud environments, limiting the attackers' ability to maintain persistent remote access channels.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration volumes and destinations would likely be significantly constrained through egress traffic inspection and policy controls, reducing the scale of sensitive data transfer to external North Korean infrastructure.
While some financial losses might still occur from initially compromised endpoints, the reduced lateral reach and constrained exfiltration paths would likely limit the total cryptocurrency theft below the $10.7 million achieved.
Impact at a Glance
Affected Business Functions
- IT Development and Software Engineering
- Cryptocurrency Trading and Digital Asset Management
- Remote Work Infrastructure
- Human Resources and Talent Acquisition
Estimated downtime: N/A
Estimated loss: $10,700,000
Compromise of over 7,000 cryptocurrency wallets with theft of private keys and seed phrases. Browser credentials, clipboard contents, keystroke logs, and sensitive documents from 30,000+ infected devices across IT professionals and developers. Potential intellectual property theft and corporate network access through lateral movement.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement from compromised developer workstations to critical enterprise networks and cryptocurrency infrastructure
- • Deploy Egress Security & Policy Enforcement to block unauthorized outbound connections and detect cryptocurrency exfiltration attempts through FQDN filtering and data loss prevention controls
- • Enable Multicloud Visibility & Control to monitor anomalous developer tool usage, detect suspicious automation patterns, and identify repeated malformed requests from compromised development environments
- • Establish Threat Detection & Anomaly Response capabilities to baseline normal developer behavior and alert on covert remote access tools, unusual cryptocurrency wallet interactions, and credential harvesting activities
- • Enforce East-West Traffic Security controls to inspect and control workload-to-workload communications, preventing compromise spread between development, staging, and production environments



