logo

North Korean Hackers Use Fake Coding Tasks to Steal Crypto

ID: 55b55dbf-fe3f-563b-84c9-f7ac96fb7aad

STIX ID: report--55b55dbf-fe3f-563b-84c9-f7ac96fb7aad

Feed Name: Infosecurity Magazine (News)

Threat Score
84/100

Date Published: 2026-06-08

Date Updated: 2026-06-09

...
...

A likely North Korean-linked campaign (tracked as UNK_DeadDrop) phished developers at almost 100 organizations with fake job and code-review lures, sending over 250 emails in April–May 2026 that linked to poisoned GitHub/GitLab repositories. Each repository contained a hidden tasks.json that abused editor automation (VS Code, Cursor) to install a malicious extension or run in-editor payloads; macOS/Linux victims received a Go remote access trojan and Windows victims ran JavaScript in the editor. The malware scans for browser-stored secrets and many cryptocurrency wallets (extensions and desktop apps), uses fake password prompts to escalate privileges on macOS/Linux, bypasses Chrome app-bound encryption on Windows, and exfiltrates credentials and crypto before deleting traces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.