Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hijacked Packages Deploy Python Infostealer via VS Code

Hijacked Packages Deploy Python Infostealer via VS Code

Posted on June 29, 2026 By CWS

Cybersecurity experts have identified a targeted attack involving compromised npm and Go packages that deliver a Python-based information stealer across Windows, Linux, and macOS platforms. This malicious campaign leverages Visual Studio Code (VS Code) tasks to infiltrate systems and execute harmful scripts.

Exploiting VS Code Tasks for Malware Deployment

The attack cleverly bypasses typical npm execution pathways by embedding its operations within a VS Code task, as reported by JFrog. When a project folder containing the malicious package is opened in VS Code, it automatically executes encrypted JavaScript sourced from blockchain transaction data. This initiates a connection to attacker-controlled infrastructure, deploying a socket.io backdoor and ultimately a Python infostealer.

The use of a hidden VS Code task named “eslint-check” triggers this execution. Configured to run upon opening the folder as a workspace, this task deceives developers by masquerading JavaScript code as a font file. Such tactics have been linked to North Korea, with the OpenSourceMalware team labeling this strategy as the “Fake Font” campaign.

Wide-ranging Data Theft and Persistent Access

This campaign is part of the broader “Contagious Interview” operation targeting software developers. The final payload, known as InvisibleFerret, is designed to steal sensitive data such as cryptocurrency wallets and browser credentials. It also establishes persistent access by setting up a Socket.io backdoor for remote control, including functionalities like file uploads and system command execution.

The Python loader, crucial to this operation, fetches the infostealer from the command-and-control (C2) server, targeting various credentials and data across browsers, operating system credential stores, and developer tools. This includes information from Git, GitHub, VS Code, and storage services like Dropbox and Google Drive.

Implications for the Go Ecosystem

Parallel to npm, the attack extends to the Go ecosystem, with 16 Go packages discovered to contain the same malware. These packages, appearing legitimate, have been compromised to include the malicious payload alongside their original content structure.

Security experts recommend immediate removal of these packages, thorough inspection of developer machines for hidden tasks, and rotation of sensitive credentials and tokens to mitigate the risk of data theft and unauthorized access.

This incident highlights the dual objectives of the attackers: immediate data theft and ongoing system access. The sophisticated use of a socket.io-based backdoor and the Python stage’s comprehensive credential harvesting demonstrate the attack’s complexity and potential impact.

Users and developers are urged to stay vigilant, ensuring their systems are free from such vulnerabilities and regularly updating security protocols to protect against evolving threats.

The Hacker News Tags:Blockchain, Contagious Interview, credential harvesting, Cybersecurity, data theft, Fake Font, Go packages, Malware, North Korea, npm packages, Python infostealer, remote access, Software Security, VS Code

Post navigation

Previous Post: The Necessity of 24/7 Support in Cybersecurity

Related Posts

Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence The Hacker News
295 Malicious IPs Launch Coordinated Brute-Force Attacks on Apache Tomcat Manager 295 Malicious IPs Launch Coordinated Brute-Force Attacks on Apache Tomcat Manager The Hacker News
3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation 3,000 YouTube Videos Exposed as Malware Traps in Massive Ghost Network Operation The Hacker News
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution The Hacker News
Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment The Hacker News
Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; M Stolen in Crypto Heist Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hijacked Packages Deploy Python Infostealer via VS Code
  • The Necessity of 24/7 Support in Cybersecurity
  • China’s Zhipu AI Matches U.S. Models in Cybersecurity
  • OpenAI’s Limited Release of GPT-5.6 Sol with Security Enhancements
  • RedAmon Revolutionizes Automated Penetration Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hijacked Packages Deploy Python Infostealer via VS Code
  • The Necessity of 24/7 Support in Cybersecurity
  • China’s Zhipu AI Matches U.S. Models in Cybersecurity
  • OpenAI’s Limited Release of GPT-5.6 Sol with Security Enhancements
  • RedAmon Revolutionizes Automated Penetration Testing

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark