← All news
ARTICLE
22 September 2026

WaterPlum / Contagious Interview — MSP hiring & freelancer hygiene

DRAFT, defensive only. ACSC+NPA 2026-09-18 WaterPlum/Contagious Interview: fake recruiter coding tests. Sandbox only; VS Code Restricted Mode; contractor diligence. FLAG $ as advisory-stated. No malware internals.

ACSC + NPA 2026-09-18: never run recruiter code on prod or crypto machines

On 2026-09-18, ACSC and Japan’s NPA published joint guidance on the DPRK-linked WaterPlum cluster (commonly Contagious Interview): actors pose as AI/crypto/NFT recruiters; fake coding tests deliver malware loaders.

FLAG: any $ / ¥ victim or crypto figures in coverage are advisory-stated only — do not invent or amplify numbers beyond the advisories.

FLAG — $ / ¥ figures are advisory-stated only. Do not invent victim counts, crypto-loss totals, or amplify numbers beyond ACSC / NPA advisories of 2026-09-18.

# MSP hiring / freelancer hygiene — WaterPlum / Contagious Interview — NO malware internals
1. Never run recruiter-provided code on prod or crypto machines
2. Use an isolated sandbox only for any coding-test artifact
3. Enable VS Code Restricted Mode for untrusted workspaces
4. Contractor ID + payment diligence before onboarding cold-outreach freelancers
5. FLAG any $ / ¥ figures as advisory-stated only (ACSC + NPA 2026-09-18)
6. Ban: no malware internals, no loader reproduction, no weaponized how-to

MSP eng and helpdesk posture: never run recruiter-provided code on production or crypto wallets/machines; use an isolated sandbox only; enable VS Code Restricted Mode for untrusted workspaces; apply contractor identity and payment diligence before onboarding freelancers who arrive via cold outreach.

This draft stays at defensive mitigations. No malware family internals, no loader reproduction, no weaponized how-to.

Draft only. Human publishes. Defensive mitigations only — no malware internals / no reproduction.