INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Hijacks npm and Go Packages via VS Code

| 2026-06-29 05:36 CRITICAL HIGH DATA BREACH SUPPLY CHAIN MALWARE & BOTNETS
Executive Summary
AI-generated
A cyberattack was discovered on June 29, 2026, where two hijacked npm packages and a cluster of Go packages were designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. North Korea has been attributed as the source behind this attack. The affected product includes VS Code tasks that trigger execution when the project folder is opened in VS Code, allowing malware to retrieve encrypted JavaScript from blockchain transaction data, connect to attacker-controlled infrastructure, launch a [IOC HIDDEN • LOGIN REQUIRED] backdoor, and deploy a Python infostealer. This attack works by disguising payload as font files, specifically public/fonts/fa-solid-400.woff2, which contains JavaScript code. The current status is that the two hijacked npm packages were uploaded on May 25, 2026, but are no longer available for download from the registry.
Technical Mitigations AI-generated
• Patch the "eslint-check" task in VS Code to prevent arbitrary code execution by setting its configuration options to only trigger on specific events. • Block or hunt for the TronGrid and Aptos blockchain infrastructure, as it is used as a dead drop resolver in this campaign. • Use a tool like `npm audit` to detect vulnerabilities in npm packages and ensure that dependencies are up-to-date.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ho•••••.yml
so•••••.io
ta•••••.json
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Contagious InterviewContagious Interview InvisibleFerretInvisibleFerret
Target & Sectors
Global Scope cryptocurrencycryptocurrency technologytechnology
Incident Timeline
‎May 25, 2026
Threat actors used a VS Code auto-run task to deploy a Python infostealer, disguising the payload as a font file.
infrastructure Vs Code
threat_actor Contagious Interview
‎2026/06/29
Threat actors used hijacked npm and Go packages to deploy a Python-based information stealer on compromised hosts via VS Code tasks.
infrastructure Vs Code
infrastructure Visual Studio Code
infrastructure Windows
infrastructure Linux
infrastructure Macos
infrastructure Cursor
threat_actor Contagious Interview
Tactical Metrics
Metrics
infrastructure
‎Vs Code
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Visual Studio Code
Affected Product
Metrics
infrastructure
‎Cursor
Affected Product
Intelligence Sources