GitHub’s July 18, 2023 warning described a low-volume campaign that used fake developer or recruiter identities to trick technology-firm employees into running malicious code. GitHub said the targets were approached through personal accounts and that neither GitHub nor npm systems were compromised. The alert is distinct from later reports about the WaterPlum/Contagious Interview operation; those reports describe related fake-recruitment tactics, not additional impact figures for GitHub’s 2023 campaign.
What GitHub warned about in July 2023
GitHub said it had identified a low-volume social-engineering campaign targeting personal accounts of technology-firm employees. Many identified targets had ties to blockchain, cryptocurrency or online gambling, and some worked in cybersecurity. GitHub assessed with high confidence that the campaign was associated with a group acting in support of North Korean objectives, known as Jade Sleet by Microsoft Threat Intelligence and TraderTraitor by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This is GitHub’s attribution assessment, not a publicly established identity for the operators. GitHub’s July 18, 2023 alert gives the company’s account.
GitHub also stated: “No GitHub or npm systems were compromised in this campaign.” The warning concerned attackers using social engineering and malicious code to target individuals, not a disclosed breach of GitHub’s or npm’s services.
How the reported attack worked
- Start with a convincing identity. The actor posed as a developer or recruiter using fabricated personas on GitHub and other social platforms, including LinkedIn, Slack or Telegram. GitHub said the actor could also use compromised legitimate accounts and might start a conversation on one service before moving it elsewhere.
- Build rapport and propose collaboration. After establishing contact, the actor invited the target to collaborate on a public or private GitHub repository. GitHub said the repositories could be presented as plausible projects, including media-player or cryptocurrency-trading tools.
- Persuade the target to run the project. The target was encouraged to clone and execute the repository. GitHub reported that malicious npm dependencies could act as first-stage malware, downloading and running a second-stage payload.
- Sometimes skip the repository. Some victims received malicious software directly through messaging or file-sharing platforms, according to GitHub.
GitHub said publishing packages when extending a fraudulent repository invitation was intended to limit exposure to scrutiny. A repository being hosted on GitHub, or a project using npm, is not by itself evidence of danger; the reported risk came from deceptive recruitment and malicious content.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What later fake-interview reports add—and what they do not
Subsequent reporting describes a related social-engineering theme under the name WaterPlum or Contagious Interview. It is useful context for developers and employers, but it should not be folded into GitHub’s 2023 incident: the later sources use different campaign labels and discuss broader, evolving activity.
WaterPlum figures in the 2026 joint advisory
The Australian Cyber Security Centre-hosted 2026 joint advisory on WaterPlum describes recruitment through social, job, gig-work and freelance platforms, followed by technical interviews or assignments that ask candidates to download and run malicious files hosted on developer platforms and code repositories. The advisory attributes the following impacts to WaterPlum, not to GitHub’s 2023 campaign:
Rank #2
- At least 30,000 devices infected in more than 100 countries.
- Funds or credentials from over 7,000 cryptocurrency wallets affected.
- 1.7 billion JPY (equivalent to 10.71 million USD) in cryptocurrency assets transferred to the DPRK.
Atlassian’s 2026 account of repository lures
In a September 21, 2026 update, Atlassian said fraudulent coding assessments could be hosted in public repositories on Bitbucket, GitHub or GitLab, with malicious payloads concealed in otherwise plausible code. Atlassian reported taking down hundreds of Contagious Interview repositories and associated accounts on its platforms. It also said some victims unknowingly uploaded copies of malicious repositories, becoming unintended distributors. These are Atlassian’s findings about Contagious Interview and are not GitHub’s reported 2023 impact totals.
How developers can assess a suspicious coding invitation
- Verify an unsolicited recruiter or interviewer through a contact channel you obtain independently, rather than relying only on the profile or conversation that made the approach.
- Treat requests to clone and run an unfamiliar repository, install packages, or execute a downloaded file to fix conferencing software as security decisions—even when the task looks like a credible interview exercise.
- Pause if the person shifts platforms, presses for quick execution, or offers code whose purpose and dependencies you cannot explain. Ask for a reviewable description of the assignment and a safe way to inspect it before running anything.
- If you already ran suspicious code, notify your organization’s security team promptly and follow its incident-response process. The FBI recommends evaluating activity on the suspected employee’s device and network; avoid improvising a cleanup that could destroy evidence or leave the organization unaware.
Hiring and security controls for employers
Fake recruiting can expose more than a candidate’s personal device: compromised access may create a path into company systems. The FBI’s January 23, 2025 guidance on North Korean IT workers conducting data extortion recommends least privilege, limiting installation of remote desktop software, monitoring unusual network activity and movement of code to private repositories or cloud accounts, and investigating suspicious browser sessions. It also recommends identity checks during interviews and onboarding, cross-checking duplicate applicant information, educating hiring teams, and auditing staffing firms.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Separate FBI guidance on North Korean IT worker threats to U.S. businesses from 2025 addresses hiring and identity concealment risks. It recommends checking identity documents and contact details, verifying education and work history directly, using in-person checks where possible, scrutinizing requests to change payment details, and controlling system access until checks are complete. The FBI also advises reporting suspected North Korean IT-worker activity to the FBI or IC3.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Keep the campaigns and their numbers separate
| Report | What it describes | Impact figures in the source |
|---|---|---|
| GitHub, July 18, 2023 | Low-volume social engineering against personal accounts of technology-firm employees, with repository invitations, malicious npm dependencies and other delivery routes. | No numeric impact total stated in GitHub’s alert; GitHub said its and npm’s systems were not compromised. |
| Australian Cyber Security Centre-hosted joint advisory, 2026 | WaterPlum, also referred to as Contagious Interview, targeting IT professionals through fake-recruitment and interview tactics. | At least 30,000 devices in more than 100 countries; over 7,000 cryptocurrency wallets affected; 1.7 billion JPY (10.71 million USD) in assets transferred to the DPRK. |
| Atlassian, September 21, 2026 | Contagious Interview repositories and accounts on Atlassian platforms, plus malicious assessment repositories across developer platforms. | Hundreds of repositories and associated accounts taken down, according to Atlassian. |
The reports share a broad pattern—using plausible professional opportunities to persuade people to execute code—but differ in date, naming, target population and scope. Later WaterPlum statistics cannot be used as measurements of GitHub’s 2023 warning.
Quick Recap
Best Value
- This fun, nerdy, geeky, retro Cybersecurity Awareness Month design is perfect to wear this October. Great for cyber security professionals and experts who keep people safe on the internet, safe online, and safe online.
- Wear this for October National Cyber Security Awareness Month this October, raise awareness about cyber security on smartphones, laptops at your school, in the classroom or on your college or university campus. Be safe online and make sure others are too!
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




