Threat Intelligence

MetaMask users subjected to Contagious Interview attacks

North Korean threat actors conducting Contagious Interview attacks have updated their arsenal to compromise users of MetaMask, the world's leading Ethereum wallet, with the BeaverTail and InvisibleFerret payloads, according to Cybernews.

Malicious script delivered following initial compromise facilitated manipulation of the targeted MetaMask crypto wallet extension, said cybersecurity analyst Seongsu Park in a post on X. After injecting attacker-controlled code that obtains the crypto wallet's key, attackers could then proceed to secure the master password and seed phrases before subsequently draining the targeted wallet's funds.

Such an analysis was praised by MetaMask researcher Taylor Monahan, who noted the findings' relevance for developing extensions with users commonly targeted by North Korean hackers. Cybercriminals "will always find new ways to abuse your product and circumvent any controls you have in place... If you don't care enough to stop them, they will undermine everything [you're] trying to achieve," said Monahan in a post on X.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds