Last seven days
- First activity
- Oct 6, 2026
- Last activity
- Oct 6, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 1 hostnames
ContagiousDrop is a malicious Node.js-based malware delivery system tracked by SentinelLABS and Validin under the Contagious Interview campaign cluster, which is associated with North Korean threat actors under the Lazarus umbrella.
Profile source: Mallory opens in a new tabContagiousDrop
ContagiousDrop is a malicious Node.js-based malware delivery system tracked by SentinelLABS and Validin under the Contagious Interview campaign cluster, which is associated with North Korean threat actors under the Lazarus umbrella. It has been observed embedded in fake recruitment and job assessment sites and used in ClickFix-style interview lures targeting individuals, primarily professionals in the cryptocurrency and blockchain sectors. The malware is typically implemented as Node.js applications such as app.js files and is designed to deliver payloads disguised as software updates or essential utilities. It identifies whether the victim is using Windows, macOS, or Linux and serves an OS-appropriate malware payload. Reported behavior includes notifying operators by email when victims engage with lure sites, download malicious files, or execute malicious commands, and logging victim information such as names, phone numbers, and IP addresses. Investigators reported exposed directories and logs on infrastructure including api.release-drivers[.]online, api.camdriverhelp[.]club, and api.drive-release[.]cloud, and identified email artifacts including marvel714jm[@]gmail.com and jimmr6587[@]gmail.com associated with related infrastructure. Exposed ContagiousDrop logs helped researchers identify more than 230 affected individuals between January and March 2025.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure. Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.
We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure. Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.
MITRE ATT&CK