Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1

2026-02-25 Abstract Security

https://www.abstract.security/blog/contagious-interview-evolution-of-vscode-and-cursor-tasks-infection-chains

Thumbnail for Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1

Abstract Security tracks Contagious Interview infection chains that abuse VS Code and Cursor task auto-execution to run downloader commands when developer projects are opened. New variants stage scripts through GitHub Gists, short.gy URLs, Google Drive, Vercel, and custom domains, with examples masquerading as NVIDIA or Realtek-related software. The chains target developers, including cryptocurrency and DeFi-adjacent users, and deliver payloads that lead to WeaselStore backdoors or PyArmor-protected Python malware after staged Node.js, batch, and Python execution. Detection opportunities include monitoring IDE child processes that launch curl, wget, PowerShell, or piped shell execution, and inspecting tasks.json files for suspicious gist.githubusercontent.com or staging URLs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 936835c7a98d3b223970a5d2ed63fc97 2026-02-25 2026-02-25
HASH 0959deda4982736d1c1647cff354c665 2026-02-25 2026-02-25
URL https://nomgwenya.co.za/js/sett… 2026-02-25 2026-02-25
URL https://camdriver.pro/realtekma… 2026-02-25 2026-02-25
URL https://postprocesser.com/.well… 2026-02-25 2026-02-25
URL https://nomgwenya.co.za/js/boot… 2026-02-25 2026-02-25
URL https://camdriver.pro/realtekwi… 2026-02-25 2026-02-25
DOMAIN postprocesser.com 2026-02-25 2026-02-25
DOMAIN camdriver.pro 2026-02-25 2026-02-25
DOMAIN nomgwenya.co.za 2026-02-25 2026-02-25

Related Actors

Related Reports

« Back