Fake recruitment technical test: 30,000 units targeted in Zhongzheng, money straight lifted

Japan’s National Police Agency, together with the FBI and other organizations, has identified a North Korea–linked group known as WaterPlum (also called Contagious Interview): from December 2025 to July 2026, at least 30,000 devices and targets in more than 100 countries were hit. Over 7,000 encrypted wallet data records were stolen, and related addresses received about $10.71 million.

The scam is crude but works—impersonating AI / crypto / NFT company headhunters, luring you into an online interview or a “technical test.” They get you to download an npm package, run scripts, and open a VS Code project. After the backdoor is installed, your browser passwords, clipboard contents, and seed phrases are taken too. Officials also warn that after you’ve been compromised, don’t just run antivirus—since the wallet information has already been exfiltrated, you should use a clean device to set up a new wallet, then move your funds.

If you’re actually offered “high-paying remote work” and they tell you to run a test first, don’t execute unknown code directly on your own machine. If you can’t even be bothered to set up an isolated environment, then don’t take this job.