Note
The interview wanted your wallet
The recruiter was real enough. LinkedIn, a freelance board, a coding test, a “quick fix for the video call.” The file was the interview.
On 18 September Japan’s NPA and National Cybersecurity Office, with the FBI, DC3, Australia’s ACSC, and two German services, attributed the cluster they call WaterPlum — the one the industry already knew as Contagious Interview. They say it is North Korean, under the 313 General Bureau.
The numbers in the advisory are not a blog estimate. At least 30,000 infected PCs in more than 100 countries, December 2025 through July 2026. More than 7,000 cryptocurrency wallets whose funds or credentials left. 1.7 billion yen, $10.71 million, moved to the DPRK. Targets were individual engineers, designers, crypto and Web3 people — Japan, the United States, Europe, and everywhere else someone will run a take-home test.
The lure is a job. Malicious NPM packages, a repo, a VS Code project, a troubleshooting installer for the “broken” conferencing app. Families of loaders the advisory names include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle. Once on the box they take browser creds, clipboard, keystrokes, screenshots, seed phrases. Sometimes they stay, which is how a personal laptop becomes a path into a client or an employer.
This is not a recruiting problem for HR
It is an endpoint problem for anyone who interviews in public. The victim is often a contractor. Their machine is not in your Intune. Their wallet is not your asset. Their npm cache might be on the same laptop they use to push to your repo.
If an engineer says they did a take-home for a crypto startup last winter and now their MetaMask is empty, do not start with “we don’t pay personal crypto losses.” Ask whether that laptop still has your SSO cookie, your VPN profile, your signing keys.
The Japanese side of the advisory also describes local facilitators who supplied machines, servers, IDs, and bank accounts. Police say they took that network down. The interview lures do not need those facilitators to keep working.
What I ask
Did they run unsigned code because a stranger on LinkedIn said the next round required it. Was the “company” a name they could invoice. Is the same GitHub account they use for work the one that cloned the test.
Rotate the work identities from a clean machine. Assume the interview laptop is hostile until it is reimaged. Do not debug the malware on it “to see.”
A job offer that wants you to execute their project before they execute a contract is not a pipeline. It is a loader with a calendar invite.
Cite: Fabio Correia, “The interview wanted your wallet”, 2026-09-19. https://www.fabiocti.com/notes/the-interview-wanted-your-wallet/. Markdown: https://www.fabiocti.com/notes/the-interview-wanted-your-wallet.md
Comments
Public thread on the canonical URL. GitHub login keeps this off a spam hole; replies are copied here on the next build so crawlers and models see them in the HTML.
No public replies yet.
Add a comment