{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors"},"incident":{"slug":"2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors","title":"Contagious Interview: fake developer job interviews deliver backdoors","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Software developers at enterprise solution, media and communications firms","sector":"Technology","country":"Global","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Cryptocurrency Theft","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":null,"summary":"Microsoft Defender Experts published detail in March 2026 on the long-running Contagious Interview operation, in which threat actors pose as recruiters from cryptocurrency and AI companies and run convincing technical interview processes with software developers. Victims are steered into cloning malicious NPM packages or opening booby-trapped repositories in Visual Studio Code, which auto-execute backdoors including OtterCookie, Invisible Ferret and FlexibleFerret.","how_it_worked":"The pretext is a career opportunity, and the trust signal is the ordinary shape of a developer hiring process: a recruiter approach, a screening call, then a take-home coding exercise. The malicious step is disguised as the exercise itself, because cloning a repository and running it locally is exactly what a candidate is expected to do. Payloads fire automatically from task configuration files when the repository is opened in Visual Studio Code, so no obviously suspicious action is needed. The malware then harvests API tokens, cloud credentials, cryptocurrency wallets, password manager databases, private keys, source code and clipboard contents.","lessons":"Candidate exercises and any unvetted repository should be run only in a disposable sandbox with no access to corporate credentials, wallets or password vaults.","confidence":"Confirmed","sources":[{"title":"Contagious Interview: Malware delivered through fake developer job interviews","url":"https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/","publisher":"Microsoft Security Blog"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-contagious-interview-fake-developer-job-interviews-deliver-backdoors"}}