Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

GitHub’s 2023 Warning: North Korean Social Engineering Targeted Tech Employees

GitHub’s 2023 warning described a low-volume campaign that used fake professional identities and malicious code to target technology-firm employees. Later WaterPlum reports concern separate activity, not additional figures for that alert.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GitHub’s July 18, 2023 warning described a low-volume campaign that used fake developer or recruiter identities to trick technology-firm employees into running malicious code. GitHub said the targets were approached through personal accounts and that neither GitHub nor npm systems were compromised. The alert is distinct from later reports about the WaterPlum/Contagious Interview operation; those reports describe related fake-recruitment tactics, not additional impact figures for GitHub’s 2023 campaign.

What GitHub warned about in July 2023

GitHub said it had identified a low-volume social-engineering campaign targeting personal accounts of technology-firm employees. Many identified targets had ties to blockchain, cryptocurrency or online gambling, and some worked in cybersecurity. GitHub assessed with high confidence that the campaign was associated with a group acting in support of North Korean objectives, known as Jade Sleet by Microsoft Threat Intelligence and TraderTraitor by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). This is GitHub’s attribution assessment, not a publicly established identity for the operators. GitHub’s July 18, 2023 alert gives the company’s account.

GitHub also stated: “No GitHub or npm systems were compromised in this campaign.” The warning concerned attackers using social engineering and malicious code to target individuals, not a disclosed breach of GitHub’s or npm’s services.

How the reported attack worked

  1. Start with a convincing identity. The actor posed as a developer or recruiter using fabricated personas on GitHub and other social platforms, including LinkedIn, Slack or Telegram. GitHub said the actor could also use compromised legitimate accounts and might start a conversation on one service before moving it elsewhere.
  2. Build rapport and propose collaboration. After establishing contact, the actor invited the target to collaborate on a public or private GitHub repository. GitHub said the repositories could be presented as plausible projects, including media-player or cryptocurrency-trading tools.
  3. Persuade the target to run the project. The target was encouraged to clone and execute the repository. GitHub reported that malicious npm dependencies could act as first-stage malware, downloading and running a second-stage payload.
  4. Sometimes skip the repository. Some victims received malicious software directly through messaging or file-sharing platforms, according to GitHub.

GitHub said publishing packages when extending a fraudulent repository invitation was intended to limit exposure to scrutiny. A repository being hosted on GitHub, or a project using npm, is not by itself evidence of danger; the reported risk came from deceptive recruitment and malicious content.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What later fake-interview reports add—and what they do not

Subsequent reporting describes a related social-engineering theme under the name WaterPlum or Contagious Interview. It is useful context for developers and employers, but it should not be folded into GitHub’s 2023 incident: the later sources use different campaign labels and discuss broader, evolving activity.

WaterPlum figures in the 2026 joint advisory

The Australian Cyber Security Centre-hosted 2026 joint advisory on WaterPlum describes recruitment through social, job, gig-work and freelance platforms, followed by technical interviews or assignments that ask candidates to download and run malicious files hosted on developer platforms and code repositories. The advisory attributes the following impacts to WaterPlum, not to GitHub’s 2023 campaign:

  • At least 30,000 devices infected in more than 100 countries.
  • Funds or credentials from over 7,000 cryptocurrency wallets affected.
  • 1.7 billion JPY (equivalent to 10.71 million USD) in cryptocurrency assets transferred to the DPRK.

Atlassian’s 2026 account of repository lures

In a September 21, 2026 update, Atlassian said fraudulent coding assessments could be hosted in public repositories on Bitbucket, GitHub or GitLab, with malicious payloads concealed in otherwise plausible code. Atlassian reported taking down hundreds of Contagious Interview repositories and associated accounts on its platforms. It also said some victims unknowingly uploaded copies of malicious repositories, becoming unintended distributors. These are Atlassian’s findings about Contagious Interview and are not GitHub’s reported 2023 impact totals.

How developers can assess a suspicious coding invitation

  • Verify an unsolicited recruiter or interviewer through a contact channel you obtain independently, rather than relying only on the profile or conversation that made the approach.
  • Treat requests to clone and run an unfamiliar repository, install packages, or execute a downloaded file to fix conferencing software as security decisions—even when the task looks like a credible interview exercise.
  • Pause if the person shifts platforms, presses for quick execution, or offers code whose purpose and dependencies you cannot explain. Ask for a reviewable description of the assignment and a safe way to inspect it before running anything.
  • If you already ran suspicious code, notify your organization’s security team promptly and follow its incident-response process. The FBI recommends evaluating activity on the suspected employee’s device and network; avoid improvising a cleanup that could destroy evidence or leave the organization unaware.

Hiring and security controls for employers

Fake recruiting can expose more than a candidate’s personal device: compromised access may create a path into company systems. The FBI’s January 23, 2025 guidance on North Korean IT workers conducting data extortion recommends least privilege, limiting installation of remote desktop software, monitoring unusual network activity and movement of code to private repositories or cloud accounts, and investigating suspicious browser sessions. It also recommends identity checks during interviews and onboarding, cross-checking duplicate applicant information, educating hiring teams, and auditing staffing firms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Separate FBI guidance on North Korean IT worker threats to U.S. businesses from 2025 addresses hiring and identity concealment risks. It recommends checking identity documents and contact details, verifying education and work history directly, using in-person checks where possible, scrutinizing requests to change payment details, and controlling system access until checks are complete. The FBI also advises reporting suspected North Korean IT-worker activity to the FBI or IC3.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep the campaigns and their numbers separate

Report What it describes Impact figures in the source
GitHub, July 18, 2023 Low-volume social engineering against personal accounts of technology-firm employees, with repository invitations, malicious npm dependencies and other delivery routes. No numeric impact total stated in GitHub’s alert; GitHub said its and npm’s systems were not compromised.
Australian Cyber Security Centre-hosted joint advisory, 2026 WaterPlum, also referred to as Contagious Interview, targeting IT professionals through fake-recruitment and interview tactics. At least 30,000 devices in more than 100 countries; over 7,000 cryptocurrency wallets affected; 1.7 billion JPY (10.71 million USD) in assets transferred to the DPRK.
Atlassian, September 21, 2026 Contagious Interview repositories and accounts on Atlassian platforms, plus malicious assessment repositories across developer platforms. Hundreds of repositories and associated accounts taken down, according to Atlassian.

The reports share a broad pattern—using plausible professional opportunities to persuade people to execute code—but differ in date, naming, target population and scope. Later WaterPlum statistics cannot be used as measurements of GitHub’s 2023 warning.

Quick Recap

SaleBestseller No. 2
SaleBestseller No. 4
Bestseller No. 5
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
Lightweight, Classic fit, Double-needle sleeve and bottom hem
$17.99
Best Value
Cyber Security Awareness Month Cybersecurity Fun Nerdy T-Shirt
  • This fun, nerdy, geeky, retro Cybersecurity Awareness Month design is perfect to wear this October. Great for cyber security professionals and experts who keep people safe on the internet, safe online, and safe online.
  • Wear this for October National Cyber Security Awareness Month this October, raise awareness about cyber security on smartphones, laptops at your school, in the classroom or on your college or university campus. Be safe online and make sure others are too!
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.