HomeSecurityVS Code Tasks: Stolen npm and Go packages download Python infostealer

VS Code Tasks: Stolen npm and Go packages download Python infostealer

VS Code Tasks are being exploited as a hidden attack vector in a new, sophisticated supply chain campaign discovered by researchers at JFrog . Two compromised npm packages — fetch-page-assets and html-to-gutenberg — along with a set of Go packages , were used to install a Python-based infostealer on Windows , Linux , and macOS systems , primarily targeting software developers.

See also: ZiChatBot Malware: Malicious PyPI Packages Target Windows and Linux

VS Code Tasks
VS Code Tasks: Stolen npm and Go packages download Python infostealer

The unique feature of this attack is that it completely avoids the classic npm lifecycle scripts — such as postinstall or preinstall — which are the most common vectors of malicious code in such attacks. Instead, the execution is hidden inside a VS Code Task named eslint-check , configured with the runOn: 'folderOpen' option , so that it is automatically activated as soon as the developer opens the project folder in VS Code or the Cursor IDE . This tactic seems to be a conscious adaptation to the new safeguards of npm v12 .

The two malicious packages were uploaded to the npm registry on May 25, 2026 , and have since been removed. The payload is disguised as a font file — public/fonts/fa-solid-400.woff2 — but actually contains JavaScript code. The use of fake font files in conjunction with VS Code Tasks has previously been attributed to North Korean hackers , as part of the notorious Contagious Interview campaign .

VS Code Tasks: How the infection chain works

Once the VS Code Task, the malicious code performs a series of steps to install the infostealer without arousing suspicion. First, it retrieves encrypted JavaScript from blockchain transaction data, using the TronGrid and Aptos as an alternative retrieval mechanism — a technique known as a dead drop resolver that makes the attack resistant to attempts to take down the infrastructure. It then connects to infrastructure controlled by the attackers and installs a Socket.io backdoor.

The Socket.io backdoor gives the attacker full remote control of the infected system: executing shell, collecting clipboard content, managing files, uploading files, managing processes, and executing arbitrary JavaScript. At the same time, a Python loader that downloads the main infostealer from the C2 server and installs the necessary dependencies.

See also: 'Mini Shai-Hulud': SAP-Related npm Packages Compromised with Credential Stealer

VS Code Tasks: Stolen npm and Go packages download Python infostealer
VS Code Tasks: Stolen npm and Go packages download Python infostealer

The Python infostealer is extremely broad in its scope. It steals data from Chromium- and Mozilla Firefox- based browsers , password managers, authenticators, and cryptocurrency wallets . It also targets developer-oriented information such as Git credentials , GitHub CLI hosts.yml, GitHub Desktop logs, VS Code settings , as well as data from Windows Credential Manager , Linux Secret Service , KDE Wallet , macOS Keychain , and cloud storage metadata for Dropbox , Google Drive , Microsoft OneDrive , Apple iCloud , Box , Mega , and pCloud .

VS Code Tasks and the connection to North Korean hackers

The OpenSourceMalware team is tracking this activity under the name Fake Font and describes it as a variant of the Contagious Interview campaign , which has been ongoing since 2023. The campaign targets software developers and technical staff through fake job interview processes. According to security researcher Paul McCarty , the Fake Font campaign delivers a multi-stage loader that ultimately deploys the InvisibleFerret Python backdoor , designed to steal cryptocurrency wallets , browser credentials, and establish permanent access.

This attack is part of a broader surge in software supply chain attacks during 2025–2026. The TeamPCP / Mini Shai-Hulud campaign compromised 323 npm packages to extract CI/CD secrets from the GitHub Actions Runner cache, while the TrapDoor campaign used 34 malicious packages on npm , PyPI , and Crates.io , targeting crypto and AI developers . Indicative of the scale of the problem is that the trojanized moralis-sdk package alone garnered over 2.7 million downloads .

Practical tips for protecting against attacks via VS Code Tasks

Researchers at JFrog and other security firms recommend a number of measures to protect against this type of attack. First, developers should manually check the .vscode/tasks.json in all projects and not trust tasks that are automatically executed or refer to unknown scripts. Second, it is worth checking the node_modules for size anomalies — e.g. obfuscated files of 486–498 KB — or unexpected git references to dependencies.

If an environment ran npm install after May 19, 2026 with the affected packages, it is recommended to immediately rotate all secrets: GitHub PATs, AWS/GCP/Azure credentials, Kubernetes tokens , and SSH keys. Additionally, using the npm install --ignore-scripts can prevent malicious lifecycle scripts from executing, although it does not stop VS Code Tasks. Finally, tools such as SafeDep, Phoenix Security , or SlowMist MistEye can help detect compromised packages and verify source signatures.

See also: Vulnerability in Claude Code GitHub Action allows malicious issue to take over repositories

Malicious npm packages PostCSS RAT Windows malware

This particular attack highlights how sophisticated attackers have become in exploiting tools that developers trust every day. VS Code Tasks are now an active attack vector that requires increased vigilance from the developer community, especially at a time when attacks on the software supply chain are multiplying at an alarming rate.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS