Japan’s National Police Agency and the U.S. Federal Bureau of Investigation have warned that a North Korea-linked hacking group is using fake recruitment approaches and coding tests to compromise cryptocurrency developers, freelancers and Web3 employees, stealing at least $10.71 million in digital assets and accessing more than 7,000 crypto wallets.
The campaign, attributed to a group known as WaterPlum or “Contagious Interview,” infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026, according to a joint alert issued on Sept. 18. The agencies said the operation has shifted attention from large cryptocurrency platforms and institutions toward individual workers whose laptops can provide a route into wallets, software repositories, cloud accounts and employer networks.
Victims were commonly approached through social media, job boards, gig platforms and freelancer marketplaces by people presenting themselves as recruiters or cryptocurrency-related companies. Rather than relying on conventional phishing messages, the attackers moved targets into apparent video interviews or technical assessments, then asked them to run code locally, troubleshoot a meeting problem or complete a programming task from a supplied repository.
That method turns a routine hiring practice into the initial breach. Developers are often expected to review unfamiliar code and run test projects, while many also use the same machine for browser wallets, development credentials, source-code access and communications with clients.
Malicious code hidden in interview assignments
Authorities said the fraudulent projects were presented as ordinary JavaScript, Python or Visual Studio Code workspaces. Embedded code then installed malware or launched further commands after the candidate opened the project.
The alert identified trojanized NPM packages as a recurring delivery mechanism. NPM is a widely used package manager for JavaScript projects, and compromised or malicious packages can be installed alongside otherwise plausible development dependencies.
WaterPlum also used a Visual Studio Code configuration file, .vscode/tasks.json, in some operations, authorities said. The configuration can trigger commands when a user opens and trusts a project folder. In a legitimate workspace, such tasks can automate building or testing software. In this campaign, they were used to execute malicious code on the target’s device.
Investigators linked the activity to several malware families: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. After gaining initial access, the operators deployed remote-access tools to maintain control over infected systems and used information-stealing malware to collect browser credentials, clipboard data, keystrokes, screenshots and files from local and shared drives.
The targets extended well beyond immediately available cryptocurrency balances. Authorities said the malware sought wallet private keys and seed phrases, which can give an attacker control over crypto holdings without needing the victim’s password or device. A seed phrase is the recovery credential for many self-custody wallets; anyone who obtains it can restore the wallet elsewhere.
Stolen wallet credentials can remain valuable even when a wallet is empty, the agencies said, because attackers can monitor associated addresses and wait for assets to arrive. That creates a longer-lived risk than a single unauthorized transfer.
Developer access creates a second target
The agencies said compromised developer devices can provide access to company repositories, internal services and cloud platforms. Credentials taken during a fake interview could therefore be used to pursue confidential corporate data, extortion or additional intrusions into an employer or client.
The warning also describes a connection between the hacking operation and North Korean information-technology workers who seek overseas employment under false identities. Authorities assessed that WaterPlum operators and some of these workers overlap in personnel and infrastructure, with both linked to the Munitions Industry Department’s 313 General Bureau under the Workers’ Party of Korea’s Central Committee.
The alleged employment fraud serves a different but complementary purpose: generating foreign currency through remote work while also creating opportunities to obtain access inside companies. Officials said stolen identity documents, including images of passports and driver’s licenses, were used to support false job applications.
To disguise the actual location of workers, intermediaries allegedly operated residential “remote work hubs” in foreign countries. Company-issued computers could be placed at those locations while work was performed remotely from North Korea, Russia or elsewhere, according to the alert. Intermediaries also allegedly received equipment, provided bank accounts and identity details, collected wages and forwarded payments to the operators.
Japanese authorities said they identified such a hub in Japan for the first time. The network assisted with identity masking and transferred funds worth hundreds of millions of yen out of the country, including cryptocurrency assets, according to the notice.
Interview behavior can reveal identity fraud
The joint disclosure included an example involving a Japan-based cryptocurrency firm that received an engineering application in 2025 from a person authorities assessed was likely connected to a North Korean IT worker operation. The applicant had accessed the recruitment page through a virtual private network and submitted a fabricated résumé, the agencies said.
The résumé claimed broad expertise in programming languages, blockchain technology, cryptocurrency and cloud services, along with European university education and short work placements across cities in Europe and Asia. During a video interview, the applicant said they were born in Malaysia and lived in Finland.
Authorities said the candidate’s English abilities did not appear to match the claimed education and employment history. The person could answer only simple questions and was unable to explain many of the technical skills listed in the application in detail.
Other recurring warning signs included applicants refusing in-person meetings, asking to be paid in cryptocurrency, repeatedly looking toward a second screen, background voices, and persistent audio or video delays. Officials said a second screen may be used to read answers, while a single person on camera may be receiving help from others outside the frame.
The alert also cited cases in which workers allegedly retaliated against employers during disputes, including one case involving the publication of proprietary source code and another involving the sabotage of a website.
Wallet migration may be needed after code execution
Authorities cautioned that deleting malware may not resolve the damage once unknown code has been run. Private keys, seed phrases and browser-stored credentials may already have been copied, even if no funds have moved.
They advised developers not to run untrusted code on devices that hold cryptocurrency assets or sensitive company information. When testing unfamiliar repositories is unavoidable, isolated virtual machines or sandboxes can limit the exposure of the primary workstation and its wallets.
The agencies also flagged scripts containing commands such as curl, base64, mshta and Invoke-WebRequest, which can be used to download payloads, disguise instructions or execute remote content. Such commands can have legitimate uses, but applicants should understand why they appear in an assessment before executing them.
Anyone who has run suspicious recruiter-provided code or received an antivirus alert should disconnect the device from networks and treat any wallets accessed on that machine as compromised, the agencies said. Their recommended response includes creating a new wallet on a separate, known-safe device, moving assets to it, storing the new seed phrase offline, backing up necessary files and fully reinstalling or resetting the affected operating system.
For crypto employers, the warning places greater weight on separating recruitment tests from production systems. A candidate’s coding assignment should not need access to company repositories, signing keys, browser wallets or internal cloud credentials, and technical evaluations can be conducted in controlled environments rather than on the applicant’s everyday device.
Want deeper protection tips against recruiter scams and wallet theft? Read this crypto safety standards guide to harden your defenses.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
