ARES 2026 · IWCCWe’re presenting at ARES 2026 — play a real attack in our interactive showcase
Linköping | Sweden
August 24 – 27, 2026
IWCC · 15th International Workshop on Cyber Crime

From Fake Job Offer to Full Environment Compromise

Anatomy of the Contagious Interview campaign — six trojanised “coding test” repositories, one invariant five-stage kill chain, and the behavioural signals that survive the operators’ evasion. Presented at IWCC, the cybercrime workshop of ARES 2026.

The talk

01/04
ConferenceARES 2026 — 21st International Conference on Availability, Reliability and SecurityConference site
WorkshopIWCC — 15th International Workshop on Cyber Crime
VenueConcert & Congress Hall, Linköping, Sweden
DatesAugust 24 – 27, 2026
SessionIWCC II — Cybercrime Ecosystems & Automated ReconnaissanceSession chair: Artur JanickiSonaten · Room 4Tue, August 25 · 14:30 – 16:00
The paper

From Fake Job Offer to Full Environment Compromise: Anatomy of the Contagious Interview Campaign

Abisheka Pitumpe, Jan Podleski, Amirhossein Khanlari, Amir Rahmati, Piotr Dziubecki and Devendran MuthukumaramaniAbstract

This paper presents a comparative static analysis of six trojanized npm repositories linked to the “Contagious Interview” campaign: a sustained operation targeting software engineers through fabricated job offers. Each repository was submitted independently to the analysis platform and analyzed using rule-based static scanning without code execution. The analysis reveals a shared malware framework with three invariant components: (1) automatic execution via npm lifecycle hooks, (2) full process.env exfiltration to attacker-controlled Command and Control servers, and (3) Remote Code Execution through dynamic function construction. Despite this technical uniformity, the campaign employs diverse social engineering “skins”, from DeFi platforms to World Cup NFT games, which suggests a deliberate strategy to target different developer personas. The findings have implications for software supply chain security, recruitment practices in the tech industry, and the development of automated malware detection heuristics.

Research team

02/04
Author

Amir Rahmati

Stony Brook University

Assistant Professor · Director, Ethos Lab

Author

Abisheka Pitumpe

Stony Brook University

Ph.D. Candidate · Ethos Lab

Author

Amirhossein Khanlari

Stony Brook University

Researcher

Presenting

Piotr Dziubecki

Defdone

Head of Product, RTIdx

Author

Jan Podleski

Defdone

Product Engineer, RTIdx

Author

Devendran Muthukumaramani

Kochain Technologies

Technical Product Manager

Materials

03/04
Springer · LNCSPublished paper — ARES 2026 proceedingsIn “Availability, Reliability and Security. ARES 2026 International Workshops”, Lecture Notes in Computer Science, Springer — Proceedings Part III.Read the paper Full volume
PDF · SlidesTalk slidesThe full IWCC 2026 deck — dataset, method, kill chain, clade comparison, C2 infrastructure, and attribution against G1052.Download
PDF · CLI demoCLI command orderStep-by-step commands from the live demo: install the RTIdx CLI, sign in, and scan a clean and a malicious repository.Download

Try it yourself

04/04
Interactive · 2 min

Would you have run it?

A real recruiter DM. A real repo. Play the AmonixPlay case the way the candidate lived it — then watch the kill chain fire.

Play the case
$ npm install -g @rtidx/cli
$ rtidx login
$ rtidx check https://github.com/acme/take-home-test

Check a suspicious “technical assignment” before you run it — the CLI uses the same detection pipeline that powers rtidx.com case reports.

@rtidx/cli on npm
Attending ARES 2026? Come talk to us about recruitment-driven malware, indicator sharing, or joint research.
Get in touch