OFICIAL Atlassian Blog

From fake interviews to malicious repositories: Disrupting Contagious Interview

What happened
Based on Atlassian Blog · Sep 21, 2026

Atlassian disrupts Contagious Interview, a North Korea-linked campaign using fake coding assessments to distribute malware via Bitbucket, GitHub, and GitLab repositories.

From fake interviews to malicious repositories: Disrupting Contagious Interview
Atlassian Blog — Atlassian
Key points
·
Contagious Interview campaign attributed with high confidence to North Korean threat actors using fake coding assessments to distribute malware.
·
Hundreds of malicious repositories and accounts linked to Contagious Interview have been taken down by Atlassian and industry partners.
·
Victims were tricked into uploading copies of malicious repositories, unknowingly becoming part of the campaign’s distribution chain.

A persistent campaign named Contagious Interview, attributed to North Korean threat actors, has targeted software developers through fraudulent recruitment processes. Victims were invited to complete coding assessments hosted in seemingly legitimate repositories on platforms like Bitbucket, GitHub, and GitLab. The repositories contained thousands of lines of plausible code with malicious payloads hidden in only a few files, designed to steal credentials, cryptocurrency wallets, API tokens, and corporate system access.

Atlassian collaborated with industry peers and security researchers to track and disrupt Contagious Interview activity. The company has taken down hundreds of malicious repositories and associated accounts, with detection improving through ongoing collaboration and threat intelligence. Atlassian’s Acceptable Use Policy prohibits malicious content, and the company actively responds to violations, though no action is required from Bitbucket customers.

Research identified recurring patterns in the campaign, including reused repository themes, convincing front companies with custom domains and LinkedIn profiles, and infrastructure overlaps with other North Korea-attributed activity. Threat actors frequently used similar naming conventions and project structures, with only minor differences in files concealing malicious code, making detection challenging.

The campaign’s initial loader, BeaverTail, was executed through multiple techniques, with nearly half of repositories using two or more methods. Victims were sometimes asked to record themselves completing assessments and upload copies, inadvertently becoming part of the distribution chain. Atlassian published a full research report detailing tradecraft, indicators of compromise, and security best practices to help individuals and organizations strengthen defenses.

Original source → Deals on Clipraptor.com →