Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hijacked Packages Deploy Python Infostealer via VS Code

Hijacked Packages Deploy Python Infostealer via VS Code

Posted on June 29, 2026 By CWS

Cybersecurity experts have identified a targeted attack involving compromised npm and Go packages that deliver a Python-based information stealer across Windows, Linux, and macOS platforms. This malicious campaign leverages Visual Studio Code (VS Code) tasks to infiltrate systems and execute harmful scripts.

Exploiting VS Code Tasks for Malware Deployment

The attack cleverly bypasses typical npm execution pathways by embedding its operations within a VS Code task, as reported by JFrog. When a project folder containing the malicious package is opened in VS Code, it automatically executes encrypted JavaScript sourced from blockchain transaction data. This initiates a connection to attacker-controlled infrastructure, deploying a socket.io backdoor and ultimately a Python infostealer.

The use of a hidden VS Code task named “eslint-check” triggers this execution. Configured to run upon opening the folder as a workspace, this task deceives developers by masquerading JavaScript code as a font file. Such tactics have been linked to North Korea, with the OpenSourceMalware team labeling this strategy as the “Fake Font” campaign.

Wide-ranging Data Theft and Persistent Access

This campaign is part of the broader “Contagious Interview” operation targeting software developers. The final payload, known as InvisibleFerret, is designed to steal sensitive data such as cryptocurrency wallets and browser credentials. It also establishes persistent access by setting up a Socket.io backdoor for remote control, including functionalities like file uploads and system command execution.

The Python loader, crucial to this operation, fetches the infostealer from the command-and-control (C2) server, targeting various credentials and data across browsers, operating system credential stores, and developer tools. This includes information from Git, GitHub, VS Code, and storage services like Dropbox and Google Drive.

Implications for the Go Ecosystem

Parallel to npm, the attack extends to the Go ecosystem, with 16 Go packages discovered to contain the same malware. These packages, appearing legitimate, have been compromised to include the malicious payload alongside their original content structure.

Security experts recommend immediate removal of these packages, thorough inspection of developer machines for hidden tasks, and rotation of sensitive credentials and tokens to mitigate the risk of data theft and unauthorized access.

This incident highlights the dual objectives of the attackers: immediate data theft and ongoing system access. The sophisticated use of a socket.io-based backdoor and the Python stage’s comprehensive credential harvesting demonstrate the attack’s complexity and potential impact.

Users and developers are urged to stay vigilant, ensuring their systems are free from such vulnerabilities and regularly updating security protocols to protect against evolving threats.

The Hacker News Tags:Blockchain, Contagious Interview, credential harvesting, Cybersecurity, data theft, Fake Font, Go packages, Malware, North Korea, npm packages, Python infostealer, remote access, Software Security, VS Code

Post navigation

Previous Post: The Necessity of 24/7 Support in Cybersecurity
Next Post: OpenAI Introduces Advanced Cybersecurity AI GPT-5.6 Sol

Related Posts

Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257) Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257) The Hacker News
AI Tools Fuel Brazilian Phishing Scam While Efimer Trojan Steals Crypto from 5,000 Victims AI Tools Fuel Brazilian Phishing Scam While Efimer Trojan Steals Crypto from 5,000 Victims The Hacker News
Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices Ukrainian Network FDN3 Launches Massive Brute-Force Attacks on SSL VPN and RDP Devices The Hacker News
GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms GPUGate Malware Uses Google Ads and Fake GitHub Commits to Target IT Firms The Hacker News
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link The Hacker News
ServiceNow AI Platform Security Flaw Under Attack ServiceNow AI Platform Security Flaw Under Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phantom Stealer Conceals in PNG Files, Targets Data
  • VMware vCenter Vulnerability Exploited by Hackers
  • Akira Ransomware Exploits Safe Mode to Bypass Security
  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phantom Stealer Conceals in PNG Files, Targets Data
  • VMware vCenter Vulnerability Exploited by Hackers
  • Akira Ransomware Exploits Safe Mode to Bypass Security
  • Critical Cisco Firewall Vulnerability Urges Immediate Action
  • SharePoint Vulnerability Abused After PoC Emerges

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark