Threat Actors Expand Abuse of Microsoft Visual Studio Code

2026-01-20 Jamf

https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/

Thumbnail for Threat Actors Expand Abuse of Microsoft Visual Studio Code

Jamf Threat Labs describes an evolution of the DPRK-linked Contagious Interview campaign that abuses Microsoft Visual Studio Code task configuration files in malicious GitHub or GitLab repositories. Under recruitment or technical-assignment lures, a victim who opens and trusts the repository in Visual Studio Code can trigger tasks.json commands that run shell, curl a remote JavaScript payload, and pipe it into Node.js on macOS. The JavaScript implant provides host fingerprinting, public IP discovery through ipify.org, five-second command-and-control polling, and remote code execution through server-supplied JavaScript. Jamf also observed follow-on JavaScript tasking roughly eight minutes after infection, underscoring how the campaign adapts delivery and execution to normal developer workflows.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 932a67816b10a34d05a2621836cdf7f… 2026-01-20 2026-01-20

Related Actors

Related Reports

« Back