Scworld
North Korean Hackers Weaponize VS Code in Contagious Interview Campaign
First seen 22 Jan 2026, 21:42 UTC
•

•21.0
Export
Article Content
Browse articles
The Contagious Interview campaign has seen North Korean threat actors exploiting Microsoft Visual Studio Code (VS Code) to compromise software engineers in sectors like cryptocurrency and fintech. By embedding malicious logic into VS Code project configurations, attackers can execute harmful commands when victims open a repository and grant it trust. This evolution in tactics was highlighted in recent research from Jamf Threat Labs and OpenSourceMalware.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
Recent
Jamf Threat Labs identifies abuse of VS Code in Contagious Interview campaign
Date unknown
Malicious Git repository automates execution of harmful commands
Date unknown
Research from OpenSourceMalware released on evolving techniques
More articles in this cluster
Continue Reading
DPRK-Linked Malware Targeting Job Seekers via Wellfound
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign