North Korean Hackers Use Fake Coding Tasks to Steal Crypto
ID: 55b55dbf-fe3f-563b-84c9-f7ac96fb7aad
STIX ID: report--55b55dbf-fe3f-563b-84c9-f7ac96fb7aad
Feed Name: Infosecurity Magazine (News)
A likely North Korean-linked campaign (tracked as UNK_DeadDrop) phished developers at almost 100 organizations with fake job and code-review lures, sending over 250 emails in April–May 2026 that linked to poisoned GitHub/GitLab repositories. Each repository contained a hidden tasks.json that abused editor automation (VS Code, Cursor) to install a malicious extension or run in-editor payloads; macOS/Linux victims received a Go remote access trojan and Windows victims ran JavaScript in the editor. The malware scans for browser-stored secrets and many cryptocurrency wallets (extensions and desktop apps), uses fake password prompts to escalate privileges on macOS/Linux, bypasses Chrome app-bound encryption on Windows, and exfiltrates credentials and crypto before deleting traces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
