Threat Actors Expand Abuse of Microsoft Visual Studio Code
ID: b856a2f6-bbf9-5269-bdc3-ef4c68eb8dc9
STIX ID: report--b856a2f6-bbf9-5269-bdc3-ef4c68eb8dc9
Feed Name: Jamf Blog
Threat Score
Jamf Threat Labs documents a DPRK-linked campaign that abuses Visual Studio Code task configuration files in malicious Git repositories to execute obfuscated Node.js JavaScript payloads, establishing a persistent backdoor with remote code execution and frequent C2 beaconing; the report includes technical analysis of the payloads, C2 infrastructure, and IOCs (Vercel URLs, C2 IP/DNS, multiple SHA256s) and recommends defensive controls and cautious handling of untrusted repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
