Tech-Tales and Tasty Trials! – Exploring Tech, Tastes, and Terrains!

Recent News

Copyright © 2025. All Right Reserved.

Hackers Are Using Fake Coding Tests to Infect Thousands of Devices

Share It:

Table of Content


A coding test can be an ordinary part of a technology job interview. But a new cyber campaign is turning that familiar process into a trap.

Security agencies from Japan, the United States, Australia and Germany have warned about WaterPlum, also known as Contagious Interview, a cyber threat group targeting software developers and other IT professionals through fake job offers and technical assignments.

The campaign has infected at least 30,000 devices across more than 100 countries and compromised information from more than 7,000 cryptocurrency wallets, according to the joint advisory published on September 18, 2026. The agencies say approximately 1.7 billion Japanese yen, equivalent to $10.71 million, in cryptocurrency was transferred to wallets controlled by the attackers.


Malicious coding repository disguised as a job test

How the Fake Coding Test Works

The attack begins with something that looks completely normal: a job opportunity.

Attackers often pose as recruiters or representatives of legitimate companies, sometimes impersonating businesses involved in artificial intelligence, cryptocurrency or NFTs. They approach developers through social media, recruitment platforms, freelance marketplaces and other online channels, using seemingly legitimate job opportunities to gain their trust.

After establishing contact, the fake recruiter may arrange an online interview.

The candidate is then given a technical assignment or asked to troubleshoot a problem. Instead of simply answering questions, the candidate may be instructed to download a project, repository, package or other file and run it on their computer.

That is where the attack begins.

The coding project may contain hidden malicious code. As a result, what appears to be a normal programming exercise can become a delivery mechanism for malware.


Why Developers Are Being Targeted

Developers are particularly valuable targets because their computers often contain information that goes beyond personal files.

A developer’s machine may contain:

  • Browser passwords and session information
  • API keys
  • Source code
  • Cloud credentials
  • Git repositories
  • Cryptocurrency wallets
  • SSH keys
  • Access tokens
  • Customer information
  • Company documents

Once attackers gain access to one developer’s computer, the compromise may therefore extend beyond the individual.

Atlassian recently described the same Contagious Interview technique as malicious repositories disguised as legitimate coding assessments. The repositories can contain large amounts of normal-looking code while hiding malicious components inside a small part of the project.


What Happens After the Malware Runs?

The malware used in these campaigns is designed to steal information and maintain access to compromised systems.

Security researchers have linked Contagious Interview activity to malware families including BeaverTail, InvisibleFerret and OtterCookie. These tools can be used to steal credentials, cryptocurrency wallet information, files and other sensitive data.

The attackers may also obtain information from the clipboard and capture keystrokes.

That creates a serious risk for people who enter passwords, wallet credentials or other sensitive information on an infected machine.

The danger does not necessarily end when the fake interview finishes. Some of the malware provides persistent access, allowing attackers to continue interacting with the compromised device.


The Attack Has Already Reached 100+ Countries

This is not a small campaign targeting one company or one region.

The joint advisory says WaterPlum compromised at least 30,000 PCs between approximately December 2025 and July 2026, with victims spread across more than 100 countries and regions.

The primary targets included web designers, software engineers and specialists working in cryptocurrency, blockchain and Web3.

More than 7,000 cryptocurrency wallets were affected, while the attackers transferred approximately $10.71 million in cryptocurrency to wallets associated with the operation.

The scale shows why fake recruitment has become an important cybersecurity problem for technology workers.


The Coding Test Does Not Have to Look Suspicious

One reason this technique is dangerous is that the malicious project can look legitimate.

Researchers at Elastic Security Labs previously documented a Contagious Interview campaign in which attackers used realistic coding projects containing malicious components. In one campaign, malware was hidden inside an SVG image using steganography, making the malicious content harder to identify through ordinary inspection.

This means a developer cannot always determine whether a project is safe simply by looking through a few files.

A repository can contain thousands of lines of genuine-looking code while hiding a much smaller malicious component.


Fake Recruiters Can Look Convincing

The social engineering is an important part of the attack.

Attackers may use professional-looking profiles, realistic job descriptions and company names that sound familiar. They may also understand the technical skills listed on a candidate’s resume.

Security agencies have warned that suspicious recruitment activity can include unusual interview behavior, requests for cryptocurrency payments and inconsistencies in an applicant’s claimed background. The joint advisory also recommends independently verifying recruiters and applicants rather than relying only on online profiles.

The same lesson applies to both sides of the hiring process.

Developers need to verify employers before running their software, while companies need to verify candidates before giving them access to internal systems.


How Developers Can Protect Themselves

The safest approach is to treat code received from an unknown recruiter as untrusted software.

Developers can reduce the risk by following several basic precautions:

Verify the Job First

Check whether the position exists on the company’s official careers website.

Do not rely only on a recruiter profile or a message received through social media.

If a company is supposedly hiring, contact the company through an independently verified channel and confirm that the recruiter and position are legitimate.


Do Not Run Unknown Code on Your Main Computer

A coding assignment should not automatically receive access to your personal files, passwords or cryptocurrency wallets.

If you must examine an unfamiliar project, use an isolated testing environment such as a properly configured virtual machine or sandbox.

The goal is to separate untrusted code from the computer and accounts that contain valuable information.


Keep Wallets Away From Development Machines

Anyone working with cryptocurrency should be particularly careful.

A development computer that frequently runs third-party projects should not also be the primary machine used to manage valuable cryptocurrency assets.

Separating these activities can reduce the damage if malware compromises the development environment.


Be Careful With Packages and Dependencies

A coding project may contain third-party dependencies that execute automatically during installation or development.

Developers should inspect dependency names, package sources and project instructions before installing anything.

A familiar programming workflow does not automatically mean the downloaded components are safe.


What Companies Need to Watch For

The problem also affects employers.

A compromised developer can unintentionally bring stolen credentials or malware into a company environment.

Organizations hiring remote developers should therefore verify applicants, use controlled development environments and provide only the minimum access required for a particular task.

Companies should also monitor unusual authentication activity, unexpected access to repositories and suspicious behavior from newly created accounts.

The recruitment process itself has become part of the security boundary.


Why This Attack Matters Beyond Cryptocurrency

The $10.71 million cryptocurrency theft is one of the most visible parts of the campaign, but the risk is broader.

Stolen credentials can potentially provide access to personal accounts, company systems, cloud services and development environments.

The international advisory also warns that stolen identity documents can be used for further impersonation, while compromised credentials may expose personal information, trade secrets and other corporate data.

This makes the campaign relevant even to developers who do not own cryptocurrency.


The New Rule for Online Coding Tests

Technical interviews are becoming another place where cybersecurity awareness matters.

A developer may normally think of a coding test as a harmless programming exercise. But when the assignment comes from an unverified source, the code itself can become the attack.

The safest mindset is simple:

A coding test is still software. Treat unfamiliar software as untrusted until the source and environment have been verified.

WaterPlum’s campaign demonstrates why that distinction matters. A fake job opportunity can lead from a recruiter message to a coding assignment, from the assignment to malware, and from one compromised computer to stolen credentials, cryptocurrency and corporate information.

For developers searching for their next job, checking the employer is no longer enough. The code you are asked to run deserves the same level of scrutiny.


Bharat Thakurathi

Leave a Reply

Your email address will not be published. Required fields are marked *

Grid News

Latest Post

Find Us on Youtube

Tech-Tales and Tasty Trials! — Exploring Tech, Tastes, and Terrains!
Join me, A CS grad passionate about Tech, as I explore the world—savoring flavors, uncovering innovations, and blending tech with travel. Let’s decode the world, one byte at a time!

Latest News

Most Popular

Copyright © 2025 All Right Reserved.