Urgent.News

What's breaking now, across thousands of outlets.

Tech

WaterPlum: North Korean Campaign Infects 30,000 Devices via Fake Interview Tasks

1. Basic Information Original Title: North Korean "WaterPlum," commonly referred to as “Contagious Interview,” Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe Source: National Police Agency, NCO, FBI, DC3, ASD's ACSC, BND, BfV Publication Date: 2026-09-18 Update Date: None Severity: Critical Basis for Severity: Government…

The North Korean cyber group known as WaterPlum, also called "Contagious Interview," has infected roughly 30,000 devices across over 100 countries since December 2025. They targeted IT professionals through fake interviews and coding tasks, distributing malware disguised as npm packages or VS Code projects. This malware, including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle, stole personal information, established persistent access via remote access tools (RATs), and allowed the group to compromise organizations employing or contracting with the affected victims.

The group used various tactics, such as fake resumes, VPNs, AI-powered impersonation, and laptop farms, to infiltrate corporations. Victims received seemingly legitimate job offers, technical interview invitations, or troubleshooting steps, while administrators noticed unapproved npm packages, execution from external repositories, unfamiliar VS Code workspaces, and unauthorized access to sensitive data.

The impact of these attacks included the theft of crypto wallets, browser credentials, identification documents, screenshots, keystrokes, and corporate data.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity Basis: Researchers achieved RCE on OpenAI Forums via a…

  • Attackers exploited heap overflow in libheif library to execute arbitrary code (RCE)
  • Overprivileged SSO token allowed access to ChatGPT/Codex employee account
  • Attackers created proof-of-concept pull request in internal OpenAI repository

Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

1. Basic Information Original Title: Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Source: LastPass TIME / Delphos…

  • Signed kernel driver disables EDR by terminating antivirus processes
  • Fake GitHub repositories distribute malware via DLL side-loading
  • Malware steals data and transmits to command and control server

More from Saturday 19 September →