Skip to content
North Korean Hackers Weaponize VS Code in Contagious Interview Campaign

North Korean Hackers Weaponize VS Code in Contagious Interview Campaign

First seen 22 Jan 2026, 21:42 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

The Contagious Interview campaign has seen North Korean threat actors exploiting Microsoft Visual Studio Code (VS Code) to compromise software engineers in sectors like cryptocurrency and fintech. By embedding malicious logic into VS Code project configurations, attackers can execute harmful commands when victims open a repository and grant it trust. This evolution in tactics was highlighted in recent research from Jamf Threat Labs and OpenSourceMalware.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

Recent
Jamf Threat Labs identifies abuse of VS Code in Contagious Interview campaign
Date unknown
Malicious Git repository automates execution of harmful commands
Date unknown
Research from OpenSourceMalware released on evolving techniques

More articles in this cluster (3)

Following this threat?

Track Tsunami and Vercel in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed