logo

Malicious VS Code tasks.json abuse enables multi-stage infostealer deployment

ID: 07bd1ca6-a390-515f-a9b7-f11326af20b5

STIX ID: report--07bd1ca6-a390-515f-a9b7-f11326af20b5

Feed Name: ThreatLocker Blog

Threat Score
70/100

Date Published: 2026-02-02

Date Updated: 2026-05-01

...
...

ThreatLocker analyzed a malicious VS Code tasks.json that, once a project is marked trusted, downloads and executes multi-stage Node.js payloads to install a feature-rich infostealer. The payloads perform user and host enumeration, initialize an LDB component, recursively scan and exfiltrate sensitive files, continuously capture clipboard contents, and communicate with attacker infrastructure via Axios and WebSockets. The report includes SHA-256s, domains, an IP, analysis of obfuscation and anti-analysis techniques, and practical mitigation and hardening recommendations for developer environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.