North Korean Hackers Exploit Visual Studio Code to Deploy Backdoor Malware via Git Repositories
By
vinnyglennon
Front-window bakery material. Catches the eye, delivers the goods.
Summary
Jamf Threat Labs has identified North Korean threat actors expanding their abuse of Microsoft Visual Studio Code to deploy backdoor malware. The Contagious Interview campaign now uses malicious Git repositories to infect developers through VS Code extensions, marking an evolution in the attack technique. The campaign targets developers and IT professionals by compromising legitimate development workflows.
Key quotes
· 4 pulledJamf Threat Labs identifies additional abuse of Visual Studio Code. See the latest evolution in the Contagious Interview campaign.
Jamf Threat Labs published research related to the Contagious Interview campaign, which has been attributed to a threat actor operating on behalf of North Korea (DPRK).
Researchers from OpenSourceMalware (OSM) released additional findings that highlighted an evolution in the technique.
The Contagious Interview campaign now uses malicious Git repositories to infect developers through VS Code extensions.
You might also wanna read
Glassworm Malware Campaign Targets Developers via npm, PyPI, OpenVSX, and GitHub
Glassworm is a dangerous malware campaign targeting software developers by abusing trusted platforms including npm, PyPI, OpenVSX, and GitHu
cybersecuritynews.com·4d agoVS Code Remote-SSH Vulnerability Enables Lateral Movement from Developer Machines to Cloud Servers
A critical vulnerability in Visual Studio Code's Remote-SSH extension creates a post-compromise attack path enabling threat actors to pivot
cybersecuritynews.com·2d agoNorth Korean Chollima Group Targets PHP Developers via Malicious Packagist Package
A malicious obfuscated JavaScript payload was discovered appended to tailwind.js in the Packagist development version dev-drewroberts/featur
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
SymJack Attack Exploits AI Coding Agents for Supply Chain Compromise
This article describes a novel supply chain attack called 'SymJack' that targets AI coding agents. The attack exploits the trust and automat
