logo

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

ID: a0805988-6963-5b0f-a9f6-e96d3214d081

STIX ID: report--a0805988-6963-5b0f-a9f6-e96d3214d081

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-29

Date Updated: 2026-07-01

Author: [email protected] (The Hacker News)

...
...

This report describes a multi-stage supply-chain campaign that delivered a Python infostealer (InvisibleFerret) through hijacked npm packages (notably html-to-gutenberg and fetch-page-assets) and 16 compromised Go repositories; the attackers hide JavaScript payloads as font files, trigger execution via a VS Code 'runOn: folderOpen' task, fetch encrypted payloads from blockchain transaction data, deploy a socket.io backdoor, and ultimately steal browser credentials, cryptocurrency wallets, developer artifacts, OS credential stores, and cloud metadata before exfiltration. JFrog and Nextron analysts link the activity to the Fake Font / Contagious Interview campaign (possible evolution with prior North Korea-associated tactics) and advise removing the packages, searching for hidden VS Code tasks, and rotating all exposed credentials and tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.