logo

Contagious Interview: Tracking the VS Code Tasks Infection Vector

ID: 80343886-35a5-5aed-93b6-aac6e11dd86b

STIX ID: report--80343886-35a5-5aed-93b6-aac6e11dd86b

Feed Name: Abstract Security Blog

Threat Score
85/100

Date Published: 2026-01-20

Date Updated: 2026-04-26

...
...

This report documents a DPRK-attributed 'Contagious Interview' campaign that abuses VS Code tasks.json (runOn: folderOpen) to execute malicious commands, leading to delivery of BeaverTail and InvisibleFerret malware and distribution of a malicious npm package (jsonwebauth); it includes GitHub search queries, indicators (domains, commit emails, personas, repositories), analysis of obfuscation and payload-hosting patterns, and recommended mitigations and detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.