INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Lazarus Group Hijacks npm and Go Packages via VS Code
| 2026-06-29 05:36 CRITICAL HIGH DATA BREACH SUPPLY CHAIN MALWARE & BOTNETS
Executive Summary
AI-generated
A cyberattack was discovered on June 29, 2026, where two hijacked npm packages and a cluster of Go packages were designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. North Korea has been attributed as the source behind this attack. The affected product includes VS Code tasks that trigger execution when the project folder is opened in VS Code, allowing malware to retrieve encrypted JavaScript from blockchain transaction data, connect to attacker-controlled infrastructure, launch a [IOC HIDDEN • LOGIN REQUIRED] backdoor, and deploy a Python infostealer. This attack works by disguising payload as font files, specifically public/fonts/fa-solid-400.woff2, which contains JavaScript code. The current status is that the two hijacked npm packages were uploaded on May 25, 2026, but are no longer available for download from the registry.
Technical Mitigations AI-generated
• Patch the "eslint-check" task in VS Code to prevent arbitrary code execution by setting its configuration options to only trigger on specific events.
• Block or hunt for the TronGrid and Aptos blockchain infrastructure, as it is used as a dead drop resolver in this campaign.
• Use a tool like `npm audit` to detect vulnerabilities in npm packages and ensure that dependencies are up-to-date.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ho•••••.yml
so•••••.io
ta•••••.json
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview
InvisibleFerretInvisibleFerret
Target & Sectors
Global Scope
cryptocurrencycryptocurrency
technologytechnology
Incident Timeline
May 25, 2026
Threat actors used a VS Code auto-run task to deploy a Python infostealer, disguising the payload as a font file.
Click on any entity below to view its context and source!
infrastructure
Vs Code
"
It's worth noting that the
abuse of a VS Code auto-run task
, coupled with the
disguise of JavaScript malware
as font files, has been attributed to North Korea.
threat_actor
Contagious Interview
"This is the third sub-campaign of the Contagious Interview' campaign that has been ongoing since 2023.
2026/06/29
Threat actors used hijacked npm and Go packages to deploy a Python-based information stealer on compromised hosts via VS Code tasks.
Click on any entity below to view its context and source!
infrastructure
Vs Code
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer.
"The package hides execution inside a VS Code task, configured to run automatically when the project folder is opened in VS Code.
The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspac…
…'s also equipped to harvest developer-oriented information like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keycha…
…sers who have installed the packages are advised to remove them with immediate effect, search developer machines for hidden VS Code folder-open tasks, and rotate credentials, tokens, cloud credentials, API keys, browser-stored credentials, and wall…
infrastructure
Visual Studio Code
The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspac…
infrastructure
Windows
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.
…ormation like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain, and cloud storage metadata for Dropbox, Google…
infrastructure
Linux
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.
…s, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain, and cloud storage metadata for Dropbox, Google Drive, Microsoft OneDrive,…
infrastructure
Macos
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.
…sktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain, and cloud storage metadata for Dropbox, Google Drive, Microsoft OneDrive, Apple iCloud, Box, Mega, and pClou…
infrastructure
Cursor
…en Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspace folder in an IDE like VS Code or Cursor.
threat_actor
Contagious Interview
The OpenSourceMalware team, which is tracking the activity under the moniker Fake Font, has described it as a variant of
Contagious Interview
, a long-running campaign targeting software developers and technical personnel through fraudulent job in…
Tactical Metrics
Metrics
infrastructure
Vs Code
Affected Product
Click for context!
"
It's worth noting that the
abuse of a VS Code auto-run task
, coupled with the
disguise of JavaScript malware
as font files, has been attributed to North Korea.
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer.
"The package hides execution inside a VS Code task, configured to run automatically when the project folder is opened in VS Code.
The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspac…
…'s also equipped to harvest developer-oriented information like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keycha…
…sers who have installed the packages are advised to remove them with immediate effect, search developer machines for hidden VS Code folder-open tasks, and rotate credentials, tokens, cloud credentials, API keys, browser-stored credentials, and wall…
Metrics
infrastructure
Windows
Affected Product
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.
…ormation like Git credentials, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain, and cloud storage metadata for Dropbox, Google…
Metrics
infrastructure
Linux
Affected Product
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.
…s, GitHub CLI hosts.yml, GitHub Desktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain, and cloud storage metadata for Dropbox, Google Drive, Microsoft OneDrive,…
Metrics
infrastructure
Macos
Affected Product
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.
…sktop logs, VS Code, and global storage, as well as data from Windows Credential Manager, Linux Secret Service, KDE Wallet, macOS Keychain, and cloud storage metadata for Dropbox, Google Drive, Microsoft OneDrive, Apple iCloud, Box, Mega, and pClou…
Metrics
infrastructure
Visual Studio Code
Affected Product
The starting point of the attack is a hidden Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspac…
Metrics
infrastructure
Cursor
Affected Product
…en Microsoft Visual Studio Code (VS Code) task named "eslint-check" that's configured with the "runOn: 'folderOpen'" option to trigger the execution of arbitrary code when the folder is opened as a workspace folder in an IDE like VS Code or Cursor.
Intelligence Sources
The Hacker News
2026-06-29
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:17
Comprehensive Tactical Telemetry
Highly Correlated Entities
15x
organisation
Identified Entity
Microsoft Visual Studio Code
entity
6x
infrastructure
Affected Product
Vs Code
software
4x
tactic
MITRE ATT&CK Technique
T1059.007 - JavaScript
technique
2x
timeline
Temporal Reference
May 25, 2026
date
Contextual Telemetry
Context Block
5 METRICS
source region
Origin Country
Korea, Democratic People's Republic of
country
source region
Origin Region
DPRK
region
threat actor
APT Group
Contagious Interview
actor
malware
Malware Payload
InvisibleFerret
tool
general metric
Go Packages
16
go packages
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.