Contagious Interview shifts to fake Mac installers
Jamf Threat Labs (Allen Golbig, 3 September 2026) found 14 unsigned macOS DMG and PKG samples impersonating apps such as The Unarchiver and Bartender. The chain stages OtterCookie after an Intel-only Node download and tracks later fetches with a short-lived HS256 JWT. Gatekeeper still blocks the files unless the quarantine flag is removed. This is a research blog, not an indictment.

Jamf Threat Labs published a research blog on 3 September 2026 describing fake macOS installers tied to Contagious Interview. The Jamf post is by Allen Golbig. It is vendor threat research, not a government indictment.
The cluster has 14 trojanized DMG and PKG samples impersonating The Unarchiver, Presentify, PDFify, Magic Disk Cleaner, Sketch2026.2, SiteSucker Pro, RAR Extractor Max, Mp3tag, Mole, HextEdit, Folder Preview Pro, Disk Doctor Pro, ServerCat, and Bartender. Every sample is unsigned and not notarized. Gatekeeper blocks them unless the victim removes the com.apple.quarantine flag.
On the DMG path, Info.plist CFBundleExecutable points to a hidden .macos Intel-only Mach-O packaged with Bunster. The loader launches the real app as a decoy, then curls /task/mac from 162.0.239.85 on port 3000.
The PKG path installs the decoy into /Applications and stages a malicious preinstall script under /Library/Application Support/ Extra. A postinstall script then runs that staged file. Staging moves to ~/.task.
tokenlinux.sh then downloads an official Node.js Intel build from nodejs.org, which forces Rosetta on Apple Silicon, plus parser.js and package.json, runs npm install, and launches OtterCookie. OtterCookie is a Socket.IO RAT (scdata) with a browser and crypto-wallet stealer (ldata), a filesystem scanner, and a clipboard clipper via pbpaste.
The extra operational detail is how later retrievals are gated. After the first fetch, requests carry a short-lived HS256 JWT whose claims include the victim IP, a sessionId, and a step counter, so the staging server can track infection progress.
OtterCookie C2 sits at 147.124.202.205 on ports 7671, 7676, and 7679. Related domains include w3pi.social, softcus.net, pobelstudio.com, kikaiverse.com, and lalitae.com. Jamf attributes the cluster to DPRK Contagious Interview through shared infrastructure with earlier VS Code tasks.json and Git hook campaigns. GBHackers recaps the same Jamf chain and notes the interview pretext still depends on a user bypassing Gatekeeper.
Jamf says the samples may be testing or early, and they do not execute by default. Research attribution is not an indictment. Gatekeeper still blocks the files without a manual bypass.
A fake-installer wallet stealer is the same class of problem as Packagist themes that steal iOS crypto seeds. Vendor-intel writeups still need host hunting, the same posture as SecFlow agents against Asian government systems. Infrastructure seizures such as the DOJ and FBI takedown of QScan and QTRouter do not replace those host controls, and neither does a Daybreak-style defense pledge.
If you run a Mac fleet, recruiter security, or a crypto-dev desk, ban unsigned DMG and PKG files from interview workflows, use disposable VMs without wallets, browsers, or SSH keys, and alert on .macos CFBundleExecutable swaps and ~/.task.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free