logo

Hackers Exploit Visual Studio Code to Deploy Malicious Payloads on Victim Systems

ID: 6fd3f92e-d48e-5a4c-9933-609f20823dc6

STIX ID: report--6fd3f92e-d48e-5a4c-9933-609f20823dc6

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-21

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

The report describes the 'Contagious Interview' campaign in which attackers host malicious Git repositories that, when trusted in Visual Studio Code, leverage tasks.json to run nohup/curl piped into Node.js and deploy obfuscated JavaScript backdoors (hosted on vercel.app). The payloads provide remote code execution, system fingerprinting, and persistent C2 beacons; Jamf Threat Labs observed active exploitation, URL changes after takedowns, and the introduction of heavy obfuscation to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.