Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—a coding test can deliver malware if you run its project. In 2024, researchers at ReversingLabs found fake Python assessments that hid downloader code in altered packages; later reports describe related fake-interview campaigns using other delivery methods. A familiar-looking project or recruiter name is not proof that either is legitimate. Verify the opportunity independently and inspect the code before executing it.

How the Python coding-test Trojan worked

ReversingLabs reported in September 2024 that archives including Python_Skill_Assessment.zip and Python_Skill_Test.zip were used as coding-test lures associated with the VMConnect campaign. The instructions asked candidates to first make sure the project ran, then fix a bug or add a feature. One project presented itself as a password manager. That initial run could trigger the malicious behavior whether or not the candidate completed the task.

The malicious code was placed in altered Python modules, including pyperclip and pyrebase, in files such as __init__.py and compiled bytecode under __pycache__. ReversingLabs described Base64-encoded downloader code that sent an HTTP POST request to command-and-control infrastructure and executed Python commands received in response. This illustrates why a project can look like an ordinary programming exercise while executing hidden behavior when started. ReversingLabs’ 2024 analysis details the samples.

The report linked the samples to VMConnect and assessed that the campaign had connections to Lazarus Group based on code similarities and earlier Japanese CERT research. That is a researcher attribution, not publicly proven identity. ReversingLabs also documented one developer approached on LinkedIn in January 2024 by someone claiming to recruit for Capital One. The company’s name was impersonated; the report does not indicate that Capital One was involved or knew of the approach.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How fake developer interviews have evolved

The Python samples are one documented technique, not a template for every hiring scam. Later reporting describes a wider set of fake-interview campaigns and delivery chains. The reports use overlapping campaign labels and note that malware capabilities can converge, so do not assume every sample is the same program or that every incident uses Python.

Repository packages and editor tasks

Microsoft reported in March 2026 that Contagious Interview had been active since at least December 2022. Its account describes staged recruiting, technical discussions, assignments, and follow-ups, with victims directed to clone and execute NPM packages hosted on code platforms. It also describes a Visual Studio Code route: a downloaded repository’s task configuration could fetch and load a backdoor after the user granted the repository trust. Microsoft said activity associated with the campaign continued to appear in customer environments at the time of publication. Microsoft Security’s report describes these variants and their capabilities.

Microsoft says observed malware can steal credentials, cloud tokens, cryptographic keys, wallet data, files, and clipboard contents; some variants also support remote commands. It identifies OtterCookie as a widely observed backdoor in the campaign and Invisible Ferret as a Python-based follow-on backdoor in some intrusions. FlexibleFerret has Python and Go variants and can use a different delivery route, including asking a victim to paste a command after a fabricated technical error. These names describe distinct malware and variants, not a guarantee that one incident contains them all.

Payload fragments hidden in SVG images

In July 2026, Elastic Security Labs described samples from a campaign it assessed as aligned with Contagious Interview. In those samples, Base64 fragments were concealed in comments in SVG images inside a trojanized coding challenge; starting the server reconstructed and executed the payload. Elastic’s analyzed chain included credential and wallet theft, file theft, clipboard collection, and a Socket.IO remote-access Trojan. These findings apply to the samples Elastic analyzed, not to every fake interview project. Elastic Security Labs’ analysis discusses the technique and the difficulty of drawing firm boundaries between related malware families.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to tell whether a developer interview may be fake

No single sign proves an interview is fraudulent. The concern is a combination of unclear identity or provenance and pressure to execute code. Legitimate assessments can include repositories and dependencies, so use these signs to decide when to pause and verify rather than as a verdict by themselves.

  • An unexpected social-media recruiter quickly moves the conversation to direct messages or another channel.
  • You cannot verify the vacancy or recruiter through contact details you found independently on the company’s real website.
  • You are told to download an archive or repository and run it before you can reasonably inspect what it does.
  • The process creates urgency or demands repeated builds, starts, screenshots, or command execution without a clear technical reason.
  • You are asked to trust an unfamiliar VS Code repository, install unexpected dependencies, paste a command, or obtain an interview tool from an unofficial source.

The 2024 ReversingLabs findings document recruiter impersonation, plausible company names, urgency, and instructions to run a project before fixing it. Microsoft’s later reporting describes staged interviews and repository execution. Those are documented tactics, not evidence that every recruiter using them is malicious.

How to reduce the risk before running an assessment

If you are applying for the job

  1. Verify the opportunity independently. Find the company’s contact details yourself, rather than relying on a link, profile, or phone number supplied in the message. Ask the company to confirm both the recruiter and assessment.
  2. Ask to inspect the task before execution. A legitimate assessment should not require you to run unexplained code before you can understand what it does. Ask for a reviewable task or a safe, documented environment.
  3. Keep untrusted code away from valuable accounts and files. Do not run it on a work device or a personal machine containing credentials, SSH keys, cloud tokens, password stores, wallet data, or mounted personal folders.
  4. If execution is necessary, isolate it. Use a disposable environment with no sensitive accounts, personal folders, or access to work networks. Inspect repository contents and dependencies first; do not grant repository trust or run lifecycle scripts until you understand what they will do.
  5. Stop if the instructions shift toward unexplained commands. Do not paste a command or install an unofficial interview application simply because a task reports an error. Verify the request through a separate, trusted company channel.

Opening a repository in VS Code is not the same as proving it safe. In Microsoft’s reported path, granting trust to a downloaded repository allowed its task configuration to fetch and load a backdoor. Treat trust prompts and automatic task execution as decisions about what code is allowed to run.

If you manage developer hiring

  • Use disposable, isolated assessment machines without production credentials, internal source systems, or access to sensitive networks.
  • Monitor developer endpoints and build tools for suspicious repository activity and dependency execution patterns.
  • Give candidates a verified company contact and a clear way to report suspicious tasks.
  • Make the assessment’s expected commands, dependencies, and execution behavior transparent so candidates can verify the task without pressure.

Microsoft’s guidance is to treat recruitment workflows as attack surfaces and to use isolated interview environments, endpoint monitoring, and hunting for suspicious repository activity and dependency execution patterns.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you already ran code from a suspicious interview

Treat the device and secrets accessible from it as potentially exposed. This is a precaution based on the credential-theft and remote-access capabilities described in the reports; it does not mean every suspicious assessment successfully compromised a device.

  1. Disconnect the device from sensitive networks and stop using it to access accounts or systems.
  2. If it is a work device, contact your organization’s security team and follow its incident-response process.
  3. From a separate, known-clean device, change exposed passwords and revoke or rotate relevant cloud tokens, SSH keys, and other secrets.
  4. Tell the real company through independently verified contact details if its name or recruiting process was impersonated.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.