Scworld North Korean Hackers Weaponize VS Code in Contagious Interview Campaign
Article Content
Browse articles
The Contagious Interview campaign has seen North Korean threat actors exploiting Microsoft Visual Studio Code (VS Code) to compromise software engineers in sectors like cryptocurrency and fintech. By embedding malicious logic into VS Code project configurations, attackers can execute harmful commands when victims open a repository and grant it trust. This evolution in tactics was highlighted in recent research from Jamf Threat Labs and OpenSourceMalware.
Ask AI about this cluster
Answers cite the sources they use
Updated 212d ago How this analysis works
Timeline
Recent
Jamf Threat Labs identifies abuse of VS Code in Contagious Interview campaign
Date unknown
Malicious Git repository automates execution of harmful commands
Date unknown
Research from OpenSourceMalware released on evolving techniques
More articles in this cluster (3)
Following this threat?
Track Tsunami and Vercel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Go Malware Campaign Targets Terraform Providers and Go Modules Cybersecurity researchers have identified a Go-based malware campaign utilizing malicious Terraform providers and Go Modules. The campaign marks the first known instance of malware being distributed through HashiCorp's centralized repository. The affected packages include gocommunity-io/dockerd and kreuzwenker/docker…
North Korean Hackers Target Rust Developers with Job Scam North Korean threat actors are conducting a social engineering campaign targeting Rust developers and crate maintainers. The attackers lure victims into video calls under the pretense of job offers, tricking them into installing malware or executing malicious commands. The Rust Project's crates.io team issued a…