On September 18, 2026, Japanese, US, Australian and German authorities published a joint advisory on WaterPlum, a North Korean actor also known as Contagious Interview. The documented tradecraft targets IT professionals with fake job opportunities, then pushes them to download or run malicious files during a technical interview or coding test.
The advisory attributes at least 30,000 compromised devices in more than 100 countries to the campaign, as well as funds or credentials exfiltrated from more than 7,000 cryptocurrency wallets and 1.7 billion yen, or 10.71 million dollars, transferred to North Korea. This is not only candidate fraud: an infected developer workstation may hold secrets, customer access, repositories and data that connect the attack to an organization.
What the September 18 advisory says
The advisory is associated with Japan’s National Police Agency and National Cybersecurity Office, the FBI and DC3 in the United States, the ASD Australian Cyber Security Centre, Germany’s BND and Germany’s BfV. It describes WaterPlum as a North Korean cyber actor group that infiltrates job seekers’ computer networks, harvests sensitive information and steals cryptocurrency.
The cited victims are IT professionals in Japan, the United States, Europe and other countries. Targeted profiles include web designers, engineers, web freelancers and specialists in blockchain, cryptocurrency or Web3. The authorities also describe overlap between some WaterPlum actors and North Korean IT workers generating revenue abroad.
The fake-interview chain
WaterPlum approaches candidates through social media, job platforms, gig-work sites, freelance marketplaces or recruiting services. The actors present themselves as employers, sometimes impersonating legitimate AI, cryptocurrency or NFT companies. The pretext is attractive: an online interview, a technical exercise, a project to fix or a video-conferencing problem to troubleshoot.
The trap starts when the candidate downloads and runs a file hosted on a collaboration platform or code repository. The advisory names malicious NPM packages and malware families or variants including BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. In some scenarios, Visual Studio Code projects contain configuration that can execute code when the folder is opened in an environment already marked as trusted.
Data, wallets and follow-on access
After initial access, the actors can maintain backdoor connectivity, deploy remote-access tools and use infostealers to extract data. The advisory explicitly lists browser-stored authentication data, clipboard contents, keystrokes, screenshots, cryptocurrency-wallet data such as private keys or seed phrases, and files on the PC or shared folders.
For a small business, contractor or customer, the risk comes from how close candidate workstations are to real work. A freelancer may have SSH keys, deployment tokens, customer exports, ID images or open SaaS sessions on the same machine. The authorities warn that successful infections can create opportunities for espionage, intellectual-property theft and lateral movement into employer environments.
Signals to watch during recruiting
The advisory does not say every remote interview is suspicious. It points to stricter rules when an unknown recruiter asks a candidate to execute a project, script or command before the company’s identity is established. A coding test should be inspectable, isolated and run in a disposable environment; it should not require the main workstation that holds wallets, browser sessions or customer repositories.
The practical indicators are concrete: commands containing curl, base64, -enc, mshta, Invoke-WebRequest, iwr or hidden execution; an unknown VS Code project; pressure to bypass trust warnings; pressure during a video call; or an offer that is vague or unusually attractive. For organizations hiring or outsourcing development, resume inconsistencies, refusal to meet in person, cryptocurrency payment requests and unverifiable contact details should also trigger review.
What independents and organizations should change
A developer should not open an unknown repository in an environment that contains real secrets. Incoming tests should run in a virtual machine, sandbox or dedicated device without crypto wallets, useful browser cookies or customer access. Unknown VS Code projects should stay in Restricted Mode, and configuration files such as .vscode/tasks.json should be reviewed before trust is granted.
Organizations should assume that a personal or freelance device can become the first link in an incident. Accounts need to be separated by customer, tokens limited to the minimum necessary, keys easy to revoke and vendor access logged. If a recruit or contractor becomes suspicious, accounts, sessions, SSH keys, CI/CD tokens and shared secrets should be revoked before the investigation is complete.
The Soclyde connection
Soclyde cannot stop WaterPlum from sending a malicious project, clean an infected workstation or recover cryptocurrency that has already moved. Its role is narrower: help a small team avoid secret reuse, generate unique passwords, keep access in an encrypted local-first vault and quickly identify which secrets must be revoked when a developer device becomes suspect.
That discipline matters in a Contagious Interview scenario because a stolen browser password or token has less blast radius when each customer, repository, service and wallet is compartmentalized. It complements virtual machines, EDR, session revocation, key rotation and recruiting controls; it does not replace them. To build that foundation, read our local-first password manager guide or our secure password generator guide.
Key points
WaterPlum shows how technical recruiting can become a complete attack chain: fake employer, coding test, malware, session theft and exfiltration of wallets or professional data. The September 18, 2026 advisory documents a global scope and already high figures, but the useful reflexes remain operational: isolate unknown code, never test on the main machine, revoke sessions from a clean device and separate secrets by use.
For small teams, the priority is limiting the domino effect. A compromised workstation is serious; a workstation that contains reused passwords, broad tokens and active wallets is much worse. Also read our infostealer guide or contact Soclyde to organize access rotation and separation.



