HomeSecurityNorth Korean hackers abuse VS Code's automated tasks

North Korean hackers devour the automatic tasks of VS Code

The North Korean hackers behind the Contagious Interview, also known as WaterPlum, are distributing a malware family tracked as StoatWaffle via malicious Microsoft Visual Studio Code (VS Code) projects. Using VS Code's 'tasks.json' to distribute malware is a relatively new tactic adopted by the threat actor since December 2025, with the attacks exploiting the 'runOn:folderOpen' option to automatically trigger its execution whenever any file in the project folder is opened in VS Code.

See also: Polyfill supply chain attack 2024: North Korean hackers involved

VS Code
North Korean hackers devour the automatic tasks of VS Code

“This task is configured to download data from a web application on Vercel regardless of the running operating system,” NTT Security said in a report published last week. “Although we assume the running operating system is Windows in this article, the basic behaviors are the same for any operating system.” The downloaded payload first checks to see if Node.js is installed on the running environment.

If it is not, the malicious software downloads Node.js from the official website and installs it. Then it proceeds to start a download, which periodically checks an external server to receive a subsequent stage download that exhibits identical behavior, reaching another point on the same server and executing the response it receives as Node.js code.

StoatWaffle has been found to deliver two different modules:

1. A thief that records credentials and extension data stored in web browsers (browsers based on Chromium and Mozilla Firefox) and uploads them to a command and control server (C2). If the compromised system runs on macOS, it also steals the iCloud Keychain database.

2. A remote access Trojan (RAT) that communicates with the C2 server to receive and execute commands on the infected computer.

See also: The rise of North Korean hackers: $2 billion in cryptocurrencies stolen

North Korean hackers devour the automatic tasks of VS Code

The commands allow the malware to change the current working directory, list files and directories, execute Node.js code, upload files, recursively search the given directory and list or upload files matching a specific keyword, execute shell commands, and terminate itself. “StoatWaffle is a modularly designed malware implemented in Node.js and has Stealer and RAT modules,” the Japanese security vendor said.

Development coincides with various campaigns that have been launched by the threatening factor targeting the open‑source ecosystem:

  • A set of malicious npm packages distributing the PylangGhost malware , marking the first time that malware has been spread via npm packages.
  • A campaign known as PolinRider has implanted a malicious encrypted JavaScript payload into hundreds of public GitHub repositories that results in the development of a new version of BeaverTail, a known thief and downloader malware attributed to Contagious Interview.

Among those compromised are four repositories belonging to the Neutralinojs GitHub. The attack is said to have compromised the GitHub account of a long-time neutralinojs contributor with organization-level write permissions to force-feed JavaScript code that retrieves encrypted payloads on Tron, Aptos , and Binance Smart Chain (BSC) to download and execute BeaverTail.

See also: North Korean hackers exploit React2Shell to deploy EtherRAT

North Korean hackers devour the automatic tasks of VS Code

The victims are believed to have been infected through a malicious VS Code extension or an npm package.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS