Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1
2026-02-25 • Abstract Security •
Abstract Security tracks Contagious Interview infection chains that abuse VS Code and Cursor task auto-execution to run downloader commands when developer projects are opened. New variants stage scripts through GitHub Gists, short.gy URLs, Google Drive, Vercel, and custom domains, with examples masquerading as NVIDIA or Realtek-related software. The chains target developers, including cryptocurrency and DeFi-adjacent users, and deliver payloads that lead to WeaselStore backdoors or PyArmor-protected Python malware after staged Node.js, batch, and Python execution. Detection opportunities include monitoring IDE child processes that launch curl, wget, PowerShell, or piped shell execution, and inspecting tasks.json files for suspicious gist.githubusercontent.com or staging URLs.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 936835c7a98d3b223970a5d2ed63fc97 | 2026-02-25 | 2026-02-25 |
| HASH | 0959deda4982736d1c1647cff354c665 | 2026-02-25 | 2026-02-25 |
| URL | https://nomgwenya.co.za/js/sett… | 2026-02-25 | 2026-02-25 |
| URL | https://camdriver.pro/realtekma… | 2026-02-25 | 2026-02-25 |
| URL | https://postprocesser.com/.well… | 2026-02-25 | 2026-02-25 |
| URL | https://nomgwenya.co.za/js/boot… | 2026-02-25 | 2026-02-25 |
| URL | https://camdriver.pro/realtekwi… | 2026-02-25 | 2026-02-25 |
| DOMAIN | postprocesser.com | 2026-02-25 | 2026-02-25 |
| DOMAIN | camdriver.pro | 2026-02-25 | 2026-02-25 |
| DOMAIN | nomgwenya.co.za | 2026-02-25 | 2026-02-25 |