'Contagious Interview' Attack Now Delivers Backdoor Via VS Code
ID: 9f882140-632c-58d1-9a56-2bea32ba74a2
STIX ID: report--9f882140-632c-58d1-9a56-2bea32ba74a2
Feed Name: Dark Reading
Jamf Threat Labs identified a new delivery technique used by the North Korean 'Contagious Interview' campaign in which malicious Git repositories (presented as hiring/code-review exercises) abuse Visual Studio Code's trust/configuration processing to automatically run commands that download and execute a JavaScript backdoor via Node.js. The payload persists and runs invisibly on macOS developer systems even after VS Code is closed, enabling credential and data theft; the campaign targets developers in high-value areas such as blockchain and cryptocurrency and leverages social engineering on platforms like LinkedIn. Jamf recommends carefully vetting repository contents before marking them as trusted and avoiding running unvetted 'npm install' or install scripts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
