Malicious VS Code tasks.json abuse enables multi-stage infostealer deployment
ID: 07bd1ca6-a390-515f-a9b7-f11326af20b5
STIX ID: report--07bd1ca6-a390-515f-a9b7-f11326af20b5
Feed Name: ThreatLocker Blog
ThreatLocker analyzed a malicious VS Code tasks.json that, once a project is marked trusted, downloads and executes multi-stage Node.js payloads to install a feature-rich infostealer. The payloads perform user and host enumeration, initialize an LDB component, recursively scan and exfiltrate sensitive files, continuously capture clipboard contents, and communicate with attacker infrastructure via Axios and WebSockets. The report includes SHA-256s, domains, an IP, analysis of obfuscation and anti-analysis techniques, and practical mitigation and hardening recommendations for developer environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
