North Korean Hackers Exploit Visual Studio Code Projects to Deploy Backdoors
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The North Korean threat actors associated with the Contagious Interview campaign have been observed deploying malicious Microsoft Visual Studio Code (VS Code) projects as lures to deliver backdoor implants. This tactic was first discovered in December 2025 and has evolved to include sophisticated methods for executing malicious payloads on compromised systems. Security researcher Thijs Xhaflaire reported that these attacks involve instructing targets to clone repositories from platforms like GitHub, GitLab, or Bitbucket, and launch the project in VS Code under the guise of a job assessment.
The malicious projects exploit VS Code task configuration files to execute payloads hosted on Vercel domains, depending on the operating system of the infected host. The configuration is set to run every time the project folder is opened, leading to the deployment of malware such as BeaverTail and InvisibleFerret. The campaign has also been found to conceal multi-stage droppers disguised as harmless spell-check dictionaries.
Once the project is opened, VS Code prompts the user to trust the repository author, allowing the application to process the tasks.json configuration file. This can result in arbitrary commands being executed on the system. On macOS, for example, a shell command retrieves a JavaScript payload that establishes a persistent execution loop, collecting host information and enabling remote code execution.
In one instance, Jamf observed additional JavaScript instructions executing eight minutes post-infection, designed to communicate with a remote server every five seconds. The attackers are believed to be leveraging AI tools to generate some of the obfuscated JavaScript code.
The DPRK-linked actors specifically target software engineers in sectors like cryptocurrency and fintech, as they often have access to sensitive financial assets and infrastructure. Compromising these individuals could provide unauthorized access to source code, intellectual property, and digital wallets.
The campaign’s evolution reflects the attackers’ ongoing efforts to adapt their tactics for greater success in cyber espionage and financial theft. Recent investigations have revealed the use of VS Code tasks to fetch obfuscated JavaScript designed to drop backdoors and cryptocurrency miners.
As these threat actors continue to experiment with multiple delivery methods, it is crucial for developers and organizations to remain vigilant against such tactics that integrate with legitimate development workflows.
Key Takeaways
- Be cautious when cloning repositories from unknown sources, especially those claiming to be job assessments.
- Regularly review and update your VS Code settings to limit the execution of untrusted tasks.
- Monitor your systems for unusual network activity, particularly connections to unknown domains.
- Educate your team about the risks of social engineering tactics used by threat actors.
- Implement security measures such as endpoint detection and response (EDR) solutions to identify and mitigate potential threats.
Key Terms & Concepts
- Contagious Interview: In this article, Contagious Interview refers to a long-running cyber campaign linked to North Korean hackers targeting software developers.
- VS Code: In this article, VS Code refers to Microsoft Visual Studio Code, a popular code editor used by developers.
- BeaverTail: In this article, BeaverTail refers to a type of malware deployed by North Korean hackers to facilitate remote code execution.
- InvisibleFerret: In this article, InvisibleFerret is identified as another malware variant used by the attackers to maintain persistence on compromised systems.
- Vercel: In this article, Vercel refers to a platform used to host malicious payloads that the attackers leverage during their campaigns.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.