Skip to content

ContagiousDrop

ContagiousDrop is a malicious Node.js-based malware delivery system tracked by SentinelLABS and Validin under the Contagious Interview campaign cluster, which is associated with North Korean threat actors under the Lazarus umbrella.

Profile source: Mallory opens in a new tab

ContagiousDrop

Family profile

ContagiousDrop is a malicious Node.js-based malware delivery system tracked by SentinelLABS and Validin under the Contagious Interview campaign cluster, which is associated with North Korean threat actors under the Lazarus umbrella. It has been observed embedded in fake recruitment and job assessment sites and used in ClickFix-style interview lures targeting individuals, primarily professionals in the cryptocurrency and blockchain sectors. The malware is typically implemented as Node.js applications such as app.js files and is designed to deliver payloads disguised as software updates or essential utilities. It identifies whether the victim is using Windows, macOS, or Linux and serves an OS-appropriate malware payload. Reported behavior includes notifying operators by email when victims engage with lure sites, download malicious files, or execute malicious commands, and logging victim information such as names, phone numbers, and IP addresses. Investigators reported exposed directories and logs on infrastructure including api.release-drivers[.]online, api.camdriverhelp[.]club, and api.drive-release[.]cloud, and identified email artifacts including marvel714jm[@]gmail.com and jimmr6587[@]gmail.com associated with related infrastructure. Exposed ContagiousDrop logs helped researchers identify more than 230 affected individuals between January and March 2025.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Oct 6, 2026
Last activity
Oct 6, 2026
Feed role
C2 / Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Amazon.com, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Reported operators

Threat actors

2 named in public reporting
Lazarus

We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure. Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.

Contagious Interview

We have been tracking these Node.js applications under the ContagiousDrop moniker since their initial exposure. Typically implemented as app.js files, the applications distribute malware to targeted individuals and notify the threat actors via email about victim engagement.

MITRE ATT&CK

ContagiousDrop in ATT&CK

11 distinct techniques