Nohup is a threat tool/actor observed in campaigns that abuse Microsoft Visual Studio Code (VS Code).
Overview
Nohup is a threat tool/actor observed in campaigns that abuse Microsoft Visual Studio Code (VS Code). The actor purportedly leverages VS Code-related artifacts—such as extensions, templates, or dev workflows—to deliver malware to developers. This technique is significant because VS Code is widely used and its extension ecosystem can be manipulated to bypass defenses and reach software supply chains.
Related Threat Clusters
-
North Korean Hackers Weaponize VS Code in Contagious Interview Campaign
The Contagious Interview campaign has seen North Korean threat actors exploiting Microsoft Visual Studio Code (VS Code) to compromise software engineers in sectors like cryptocurrency and fintech. By embedding malicious…
3 articles · Updated January 22, 2026
Recent Intelligence Reports
- Threat Actors Expand Abuse of Microsoft Visual Studio Code — News.Ycombinator · January 22, 2026