Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
ID: a0805988-6963-5b0f-a9f6-e96d3214d081
STIX ID: report--a0805988-6963-5b0f-a9f6-e96d3214d081
Feed Name: The Hacker News
This report describes a multi-stage supply-chain campaign that delivered a Python infostealer (InvisibleFerret) through hijacked npm packages (notably html-to-gutenberg and fetch-page-assets) and 16 compromised Go repositories; the attackers hide JavaScript payloads as font files, trigger execution via a VS Code 'runOn: folderOpen' task, fetch encrypted payloads from blockchain transaction data, deploy a socket.io backdoor, and ultimately steal browser credentials, cryptocurrency wallets, developer artifacts, OS credential stores, and cloud metadata before exfiltration. JFrog and Nextron analysts link the activity to the Fake Font / Contagious Interview campaign (possible evolution with prior North Korea-associated tactics) and advise removing the packages, searching for hidden VS Code tasks, and rotating all exposed credentials and tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
