Job interviews can also become an attack entry point—this time, they’re targeting Web3 developers.

Multiple agencies, including Japan’s National Police Agency and the FBI, have disclosed that the North Korean hacking group WaterPlum (also known as Contagious Interview) lures developers into running malicious code by using fake job offers, programming tests, and project collaboration. From December 2025 to July 2026, the attacks have spread to more than 100 countries, infecting at least 30,000 devices, and stealing funds or credentials from over 7,000 cryptocurrency wallets, involving at least $10.71 million in crypto assets.

What’s even more noteworthy is that it doesn’t target a single coin price; instead, it attacks the entire chain of recruiting, outsourcing collaboration, and R&D risk control. For developers, running an unfamiliar project locally is inherently a high-risk action. For wallet-holding users, a computer that contains wallets and sensitive credentials should not directly run interview code. One scenario is that a code repository and NPM package look normal, but malicious programs have already been embedded in the background. Another scenario is that the device is first taken under control, and then wallet private keys, seed phrases, and account credentials are gradually extracted.

If the interviewer asks you to run the project locally, will you isolate the device first—or continue testing?

Figure 1: North Korean hackers use recruitment attacks to target Web3 developers · Information highlights
Image source: https://www.odaily.news/zh-CN/post/5213069