


Perceptive Security
SOC/SIEM Consultancy

Socket Threat Research Team maps a rare inside look at OtterCookie’s npm-Vercel-GitHub chain, adding 197 malicious packages and evidence of North Korean operato…
Published:
26 november 2025 om 20:13:53
Alert date:
5 december 2025 om 08:03:23
Source:
socket.dev

North Korea's Contagious Interview operation continues infiltrating the npm ecosystem with 197 new malicious packages and over 31,000 downloads. State-sponsored threat actors target blockchain and Web3 developers through fake job interviews and test assignments. The campaign shows thorough adaptation to modern JavaScript and crypto development workflows. Socket's research revealed rare insights into the GitHub infrastructure supporting this activity, including the malicious tailwind-magic npm package. This sustained campaign represents one of the most prolific npm exploitation operations by North Korean actors.
Technical details
Mitigation steps:
Affected products:
npm
GitHub
Vercel
Related links:
https://socket.dev/blog/north-korea-contagious-interview-npm-attacks?utm_medium=feed
https://socket.dev/blog/north-korea-contagious-interview-campaign-338-malicious-npm-packages
https://socket.dev/npm/package/tailwind-magic/overview/3.3.1
Related CVE's:
Related threat actors:
IOC's:
tailwind-magic
This article was created with the assistance of AI technology by Perceptive.