logo

“Contagious” Code: North Korean Hackers Infiltrate Developer Workflows via Visual Studio Code

ID: c6eb17b8-1489-5d50-aa45-9b3752b2eea4

STIX ID: report--c6eb17b8-1489-5d50-aa45-9b3752b2eea4

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Jamf Threat Labs reports that the DPRK-linked 'Contagious Interview' campaign now targets developers by embedding malicious payloads in Visual Studio Code tasks.json files and the Node.js/npm workflow (including malicious install scripts), executing obfuscated JavaScript that beacons to a C2 every five seconds; developers are urged to vet repositories, package.json, install scripts, and task configurations before marking projects as trusted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.