Cybersecurity

CONTAGIOUS INTERVIEW (WATERPLUM): HOW FAKE JOB INTERVIEWS INFECT DEVELOPERS

How the Contagious Interview campaign uses fake recruiters and coding assignments to deliver malware, steal credentials and target developer environments.

September 29, 2026·5 min read
CONTAGIOUS INTERVIEW (WATERPLUM): HOW FAKE JOB INTERVIEWS INFECT DEVELOPERS

A recruiter reached out to a developer with an attractive opportunity. The role matched the developer's skills, the company appeared legitimate, and the conversation moved through the usual stages: recruiter contact, technical discussion, interview, and finally a coding assignment.

Then came the repository.

The candidate was asked to clone the project, install its dependencies, open it in Visual Studio Code, and run the application.

For a developer, none of that is unusual.

That is exactly what the attackers were counting on.

Microsoft has tracked this activity as Contagious Interview, a campaign active since at least December 2022 that abuses legitimate-looking recruitment processes to target software developers and other technical professionals. Microsoft

The interview was not simply being used to find a victim.

The interview was the initial access technique.

The Coding Assignment

The attackers have posed as recruiters representing cryptocurrency companies, AI companies, and other technology businesses. Victims are taken through a convincing hiring process before being given a technical task.

The task may involve a repository hosted on a familiar platform such as GitHub, GitLab, or Bitbucket.

The project itself can look legitimate.

Microsoft has observed repositories presented as blockchain or software projects, with the victim instructed to execute an NPM package or work with the project inside Visual Studio Code. Microsoft

The candidate is not thinking about malware.

They are thinking about getting the job.

That difference is critical.

When the Interview Turns Into Malware Delivery

The attack becomes dangerous when the victim executes the project.

In more recent activity, Microsoft observed attackers abusing Visual Studio Code workflows.

When the victim opens the downloaded project, VS Code can ask whether they trust the repository author. If the victim grants that trust, the project's task configuration can execute.

The developer believes they are starting the coding assignment.

The attacker gets code execution.

From there, additional scripts can download and launch a backdoor.

The entire process can happen through actions that look completely normal to a developer: opening a project, installing dependencies, and running a task. Microsoft

There is no need for the attacker to convince the victim to download an obviously malicious .exe.

The developer runs the code themselves.

The Developer's Laptop Becomes the Target

Once the backdoor is active, the attackers can start looking for valuable information.

And developer machines contain a lot of it.

A single workstation may contain:

  • API keys

  • .env files

  • SSH keys

  • Git credentials

  • Cloud credentials

  • Source code

  • Password-manager data

  • Cryptocurrency wallets

  • Private keys

  • CI/CD credentials

  • Browser sessions

Microsoft has observed Contagious Interview malware searching for environment files, wallet information, password stores, cryptographic keys, source code, and other sensitive information. Some observed components can also collect clipboard data and screenshots. Microsoft

This is why the victim's profession matters.

The attacker is not simply compromising a random computer.

They are targeting a machine that may already have access to valuable systems.

The Malware Has Evolved

Contagious Interview is not associated with a single static malware sample.

One of the most widely observed components is OtterCookie, a JavaScript-based backdoor that Microsoft says evolved from a relatively simple tool for remote command execution and cryptocurrency-key discovery into a more modular information-stealing platform.

Microsoft has also observed a separate JavaScript beaconing agent capable of collecting information about the host, communicating with a remote controller, and executing attacker-supplied code.

In later stages, attackers can deploy InvisibleFerret, a Python-based backdoor that provides additional remote command execution and reconnaissance capabilities. Microsoft

A September 2026 joint advisory from the FBI, Japan's National Police Agency, Australia's cybersecurity authorities, Germany's BND and BfV, and the U.S. Department of Defense Cyber Crime Center described the broader WaterPlum activity and associated it with malware including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle. Cyber.gov.au

Why This Attack Is So Effective

The interesting part of Contagious Interview is not simply the malware.

It is the workflow.

Think about how a developer normally approaches a technical interview:

A recruiter sends a repository.

The developer clones it.

Dependencies are installed.

The project is opened in an IDE.

A command is executed.

Something doesn't work.

The developer searches for the problem and runs another command.

Every one of those actions is normal.

The attackers simply place malicious instructions inside that process.

The victim isn't necessarily being tricked into doing something obviously dangerous.

They are being manipulated into doing something completely ordinary in the wrong environment.

The Attack Can Reach Beyond One Laptop

A compromised developer endpoint can contain much more than personal files.

It may have authenticated access to private source repositories.

It may contain cloud credentials.

It may have SSH access to internal infrastructure.

It may have CI/CD tokens.

It may have access to production systems.

That means a fake interview can potentially become the first step toward a much larger intrusion.

Microsoft specifically warns that the campaign targets developer endpoints because they can provide access to source code, CI/CD pipelines, production infrastructure, and valuable credentials. Microsoft

Not every infection will lead to further compromise.

But the opportunity is there.

And that is what makes the initial infection valuable to the attacker.

The Scale Is Bigger Than a Few Fake Recruiters

The September 2026 joint advisory reported that WaterPlum had compromised at least 30,000 PCs in more than 100 countries between approximately December 2025 and July 2026.

The advisory also reported that the attackers had stolen funds or account credentials from more than 7,000 cryptocurrency wallets and transferred approximately 1.7 billion JPY in cryptocurrency assets to North Korea. Cyber.gov.au

The campaign therefore demonstrates something larger than a clever phishing technique.

Recruitment itself can become an attack surface.

What Developers Can Do

The answer is not to stop downloading code or accepting technical interviews.

The important question is where that code is executed.

An unfamiliar coding assignment should not automatically be run on a primary workstation containing production credentials, cloud sessions, SSH keys, or cryptocurrency wallets.

A dedicated virtual machine or other isolated environment can separate the interview project from sensitive systems.

Repositories should be reviewed before scripts and dependencies are executed.

VS Code projects should not automatically be trusted.

Commands supplied through interview chats should not simply be copied and executed without understanding what they do.

And instructions to disable security controls should be treated as a serious warning sign.

Microsoft specifically recommends isolated environments for coding tests and take-home assignments and advises organizations to review recruiter-provided repositories before execution. Microsoft

The Real Lesson

Contagious Interview is a good example of how modern initial access is changing.

The attacker did not necessarily need a zero-day.

They did not need to break through a company's firewall.

They did not need to convince a developer that an obvious malware file was safe.

They created a situation where the victim wanted to execute the code.

That is the important lesson.

A Git repository can become an attack vector.

An NPM package can become an attack vector.

A coding assignment can become an attack vector.

And a job interview can become an initial-access technique.

The malware is only one part of the attack.

The real weapon is the trust surrounding the process.

The attacker didn't hack the interview.

They turned the interview into the hack.

Comments

No comments yet.