SOCLYDE logo
Current languageEN
Cybersecurity newsWaterPlumContagious InterviewFake recruiting

Waterplum: fake it interviews infect thousands of developer devices

The September 18, 2026 joint advisory describes WaterPlum, also known as Contagious Interview: fake IT offers, malicious coding tests, data theft and cryptocurrency theft.

By Soclyde Team

Developer workstation isolated after a fake interview compromise

In summary

  • On September 18, 2026, Japanese, US, Australian and German authorities attributed a fake-interview campaign targeting developers and IT professionals to WaterPlum.
  • The advisory says at least 30,000 devices were infected in more than 100 countries, more than 7,000 cryptocurrency wallets were affected, and 1.7 billion yen, or 10.71 million dollars, was transferred to North Korea.
  • The risk does not stop with the applicant: browser credentials, files, ID images, source repositories and client access on a developer device can also expose employers or customers.

Explore next

Soclyde resources

Article contents

On September 18, 2026, Japanese, US, Australian and German authorities published a joint advisory on WaterPlum, a North Korean actor also known as Contagious Interview. The documented tradecraft targets IT professionals with fake job opportunities, then pushes them to download or run malicious files during a technical interview or coding test.

The advisory attributes at least 30,000 compromised devices in more than 100 countries to the campaign, as well as funds or credentials exfiltrated from more than 7,000 cryptocurrency wallets and 1.7 billion yen, or 10.71 million dollars, transferred to North Korea. This is not only candidate fraud: an infected developer workstation may hold secrets, customer access, repositories and data that connect the attack to an organization.

What the September 18 advisory says

The advisory is associated with Japan’s National Police Agency and National Cybersecurity Office, the FBI and DC3 in the United States, the ASD Australian Cyber Security Centre, Germany’s BND and Germany’s BfV. It describes WaterPlum as a North Korean cyber actor group that infiltrates job seekers’ computer networks, harvests sensitive information and steals cryptocurrency.

The cited victims are IT professionals in Japan, the United States, Europe and other countries. Targeted profiles include web designers, engineers, web freelancers and specialists in blockchain, cryptocurrency or Web3. The authorities also describe overlap between some WaterPlum actors and North Korean IT workers generating revenue abroad.

The fake-interview chain

WaterPlum approaches candidates through social media, job platforms, gig-work sites, freelance marketplaces or recruiting services. The actors present themselves as employers, sometimes impersonating legitimate AI, cryptocurrency or NFT companies. The pretext is attractive: an online interview, a technical exercise, a project to fix or a video-conferencing problem to troubleshoot.

The trap starts when the candidate downloads and runs a file hosted on a collaboration platform or code repository. The advisory names malicious NPM packages and malware families or variants including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. In some scenarios, Visual Studio Code projects contain configuration that can execute code when the folder is opened in an environment already marked as trusted.

Data, wallets and follow-on access

After initial access, the actors can maintain backdoor connectivity, deploy remote-access tools and use infostealers to extract data. The advisory explicitly lists browser-stored authentication data, clipboard contents, keystrokes, screenshots, cryptocurrency-wallet data such as private keys or seed phrases, and files on the PC or shared folders.

For a small business, contractor or customer, the risk comes from how close candidate workstations are to real work. A freelancer may have SSH keys, deployment tokens, customer exports, ID images or open SaaS sessions on the same machine. The authorities warn that successful infections can create opportunities for espionage, intellectual-property theft and lateral movement into employer environments.

Signals to watch during recruiting

The advisory does not say every remote interview is suspicious. It points to stricter rules when an unknown recruiter asks a candidate to execute a project, script or command before the company’s identity is established. A coding test should be inspectable, isolated and run in a disposable environment; it should not require the main workstation that holds wallets, browser sessions or customer repositories.

The practical indicators are concrete: commands containing curl, base64, -enc, mshta, Invoke-WebRequest, iwr or hidden execution; an unknown VS Code project; pressure to bypass trust warnings; pressure during a video call; or an offer that is vague or unusually attractive. For organizations hiring or outsourcing development, resume inconsistencies, refusal to meet in person, cryptocurrency payment requests and unverifiable contact details should also trigger review.

What independents and organizations should change

A developer should not open an unknown repository in an environment that contains real secrets. Incoming tests should run in a virtual machine, sandbox or dedicated device without crypto wallets, useful browser cookies or customer access. Unknown VS Code projects should stay in Restricted Mode, and configuration files such as .vscode/tasks.json should be reviewed before trust is granted.

Organizations should assume that a personal or freelance device can become the first link in an incident. Accounts need to be separated by customer, tokens limited to the minimum necessary, keys easy to revoke and vendor access logged. If a recruit or contractor becomes suspicious, accounts, sessions, SSH keys, CI/CD tokens and shared secrets should be revoked before the investigation is complete.

The Soclyde connection

Soclyde cannot stop WaterPlum from sending a malicious project, clean an infected workstation or recover cryptocurrency that has already moved. Its role is narrower: help a small team avoid secret reuse, generate unique passwords, keep access in an encrypted local-first vault and quickly identify which secrets must be revoked when a developer device becomes suspect.

That discipline matters in a Contagious Interview scenario because a stolen browser password or token has less blast radius when each customer, repository, service and wallet is compartmentalized. It complements virtual machines, EDR, session revocation, key rotation and recruiting controls; it does not replace them. To build that foundation, read our local-first password manager guide or our secure password generator guide.

Key points

WaterPlum shows how technical recruiting can become a complete attack chain: fake employer, coding test, malware, session theft and exfiltration of wallets or professional data. The September 18, 2026 advisory documents a global scope and already high figures, but the useful reflexes remain operational: isolate unknown code, never test on the main machine, revoke sessions from a clean device and separate secrets by use.

For small teams, the priority is limiting the domino effect. A compromised workstation is serious; a workstation that contains reused passwords, broad tokens and active wallets is much worse. Also read our infostealer guide or contact Soclyde to organize access rotation and separation.

Frequently asked questions

What is WaterPlum or Contagious Interview?

WaterPlum, commonly referred to as Contagious Interview, is the name used in the joint advisory for a North Korean cyber actor group that poses as recruiters or employers to target developers, web freelancers and crypto/Web3 specialists.

How does the device get infected during recruitment?

The actors ask the candidate to join a technical interview, fix a video-conferencing issue or complete a coding assignment. The downloaded file or project can contain malicious NPM packages or configurations that install malware families such as BeaverTail, InvisibleFerret, OtterCookie, OtterCandy or StoatWaffle.

What should I do if I already ran a suspicious coding test?

Disconnect the device from the internet, treat cookies, passwords, SSH keys, tokens, cryptocurrency wallets and customer files as exposed, then revoke sessions from a clean device. For crypto assets, the advisory recommends creating a new wallet on a separate device and moving any remaining funds.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading