That coding test might not be a coding test

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
A September 18, 2026 joint advisory reports that North Korean-linked WaterPlum infected at least 30,000 devices in more than 100 countries around December 2025 through July 2026, using fake jobs and technical interviews to reach developers.
A malicious file does not always arrive in an obviously suspicious email. Sometimes it arrives after a recruiter says your CV has reached the next stage.
The September 18, 2026 joint advisory from Japanese, US, Australian and German agencies describes WaterPlum, also known as Contagious Interview, targeting software developers and other IT professionals through fake employers, recruiters and technical interviews.
The advisory reports activity around December 2025 through July 2026. These are cumulative figures for that period, not a claim that 30,000 devices were infected this week.
The attack looks like normal work
A target may be sent a coding project, technical test or software needed for a video call. They may be asked to run a repository, install packages, fix a bug or paste a command into a terminal. Each request can look plausible because it resembles the work the target is trying to obtain.
That is the trick: recruitment becomes the delivery mechanism. The immediate victim may be an applicant on a personal computer, but stolen browser data, credentials, sessions or cryptocurrency-wallet information can create a later risk for employers and clients.
What the joint advisory reports
The reported scale
At least 30,000 PCs or devices in more than 100 countries.
Funds or account credentials exfiltrated from over 7,000 cryptocurrency wallets.
1.7 billion JPY, equivalent to US$10.71 million, in crypto assets transferred to the DPRK, according to the advisory.
Those figures should be attributed to the advisory. In particular, “over 7,000 wallets” means funds or credentials were exfiltrated from those wallets; it does not establish that every wallet was directly drained. Likewise, “$10.71 million transferred” is the advisory's stated value and is more precise than an unqualified claim that attackers stole $10.7 million.
Why developers are particularly exposed
Developers routinely download repositories, install dependencies, run scripts and use terminals. A malicious technical assessment can therefore ask for behaviour that would normally be reasonable. Familiar tools are not proof that an unfamiliar project is safe.
A safer interview workflow
- 1Verify the recruiter, company and vacancy independently using official contact details.
- 2Prefer an official recruitment portal or assessment platform rather than an unexplained download.
- 3Treat repositories, packages and commands supplied by a contact as untrusted until checked.
- 4Use a disposable, appropriately isolated environment if you are technically able to manage one safely.
- 5Do not disable security controls or paste unexplained commands because an interviewer asks you to.
- 6Keep personal cryptocurrency wallets, password stores and business credentials away from assessment environments.
If you think you have run malware
Stop using the device for sensitive work and contact your employer's IT or security team, or an appropriate incident-response provider. Follow their instructions for safe isolation and preserving useful evidence. From a separate trusted device, the response team may advise credential and session review; do not assume that deleting one suspicious file proves the machine is clean.
Employers should brief hiring managers, separate assessment environments from production access, use least privilege and MFA, and make it easy for candidates and staff to report a suspicious interview. If business credentials may have been exposed, involve the security team promptly so sessions and access can be assessed and revoked safely.
The IT Club view
The dangerous attachment does not always arrive in a suspicious email. Sometimes somebody sends it after telling you that you have made it through to the second interview. Recruitment is part of the security boundary now, so a professional opportunity deserves the same verification as any other request to run code.
Sources and further reading
The scale, timeframe, attribution and financial figures in this article are reported values from the September 18, 2026 joint advisory.
FBI: North Korean WaterPlum (Contagious Interview) joint advisory →
FBI Internet Crime Complaint Center: advisory PDF (18 September 2026) →
Plain-English Takeaway
Treat a coding project, interview tool or video-call fix from an unverified contact as untrusted software. Verify the opportunity independently, use isolation where appropriate and involve employer IT or security support if a device may be compromised.
Frequently asked questions
What is Contagious Interview?
It is the campaign name commonly used for the North Korean cyber actor group the September 18, 2026 joint advisory calls WaterPlum. The group posed as prospective employers and recruiters to target IT professionals.
How large was the activity?
The advisory reports that, around December 2025 through July 2026, WaterPlum infected at least 30,000 PCs in more than 100 countries. It also reports funds or account credentials exfiltrated from over 7,000 cryptocurrency wallets and 1.7 billion JPY, equivalent to US$10.71 million, transferred to the DPRK.
What should I do if I ran suspicious interview code?
Stop using the affected device for sensitive work, contact your employer's IT or security team or an appropriate security professional, and follow their isolation and evidence-preservation guidance. Do not improvise destructive cleanup or continue using exposed accounts as if nothing happened.
Related Articles
Your encrypted call can still leak after it reaches your headphones
InjectEave shows how electromagnetic injection can induce analogue side-channel leakage after audio has been decrypted. It is specialist research, not evidence that criminals routinely listen to calls from 30 metres away.
Read articleThe Camera in the Room Might Not Look Like a Camera Anymore
As cameras, microphones and AI become embedded into ordinary-looking devices, workplace policies need to follow capability rather than appearance or brand.
Read articleYour Meeting-Room TV Is a Computer. Treat It Like One.
Modern smart TVs have software, network access, microphones and accounts. A screen on the wall deserves the same basic security thinking as other connected business devices.
Read article