logo

'Contagious Interview' Attack Now Delivers Backdoor Via VS Code

ID: 9f882140-632c-58d1-9a56-2bea32ba74a2

STIX ID: report--9f882140-632c-58d1-9a56-2bea32ba74a2

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-01-21

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Jamf Threat Labs identified a new delivery technique used by the North Korean 'Contagious Interview' campaign in which malicious Git repositories (presented as hiring/code-review exercises) abuse Visual Studio Code's trust/configuration processing to automatically run commands that download and execute a JavaScript backdoor via Node.js. The payload persists and runs invisibly on macOS developer systems even after VS Code is closed, enabling credential and data theft; the campaign targets developers in high-value areas such as blockchain and cryptocurrency and leverages social engineering on platforms like LinkedIn. Jamf recommends carefully vetting repository contents before marking them as trusted and avoiding running unvetted 'npm install' or install scripts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.