logo

Threat Actors Expand Abuse of Microsoft Visual Studio Code

ID: b856a2f6-bbf9-5269-bdc3-ef4c68eb8dc9

STIX ID: report--b856a2f6-bbf9-5269-bdc3-ef4c68eb8dc9

Feed Name: Jamf Blog

Threat Score
88/100

Date Published: 2026-01-19

Date Updated: 2026-07-16

...
...

Jamf Threat Labs documents a DPRK-linked campaign that abuses Visual Studio Code task configuration files in malicious Git repositories to execute obfuscated Node.js JavaScript payloads, establishing a persistent backdoor with remote code execution and frequent C2 beaconing; the report includes technical analysis of the payloads, C2 infrastructure, and IOCs (Vercel URLs, C2 IP/DNS, multiple SHA256s) and recommends defensive controls and cautious handling of untrusted repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.