TasksJacker: Latest DPRK Attack Skips the Fake Interview and Goes Straight to Compromising GitHub Users

2026-03-31 OSM

https://opensourcemalware.com/blog/tasksjacker-blog-post

Thumbnail for TasksJacker: Latest DPRK Attack Skips the Fake Interview and Goes Straight to Compromising GitHub Users

OpenSourceMalware identifies TasksJacker as an active DPRK-linked supply-chain campaign that compromises GitHub repositories by adding malicious .vscode/tasks.json files configured to run when a developer opens the folder in VS Code. The campaign affected more than 400 repositories, including DataStax projects, and used force-push history rewriting to make injected files appear as older legitimate maintainer commits. Its payload chain downloads a self-deleting dropper, retrieves encrypted references through TRON and Aptos APIs, fetches payload material from Binance Smart Chain transactions, and executes infostealer and backdoor components targeting browser credentials, cryptocurrency wallets, SSH keys, AWS credentials, environment variables, and Git tokens. The activity matters for DPRK tracking because it moves beyond fake-interview lures into direct open-source ecosystem compromise, with resilient blockchain-based C2 and follow-on evolution into PolinRider-style upstream injection activity.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN api.trongrid.io 2025-10-27 2026-05-31
DOMAIN fullnode.mainnet.aptoslabs.com 2025-10-27 2026-05-31
DOMAIN outlook.com 2018-09-06 2026-04-17
DOMAIN bsc-dataseed.binance.org 2025-10-27 2026-04-11
DOMAIN bsc-rpc.publicnode.com 2025-10-27 2026-04-11
YARA TasksJacker_Blockchain_IOCs 2026-03-31 2026-03-31
EMAIL [email protected] 2026-03-31 2026-03-31
EMAIL [email protected] 2026-03-31 2026-03-31

Related Reports

« Back