Security Warning: Visual Studio Code Being Abused to Execute Malicious Payloads
North Korean cyber actors are targeting developers by hiding malware in Microsoft Visual Studio Code configuration files. Using fake recruitment repositories, this campaign exploits the tasks.json feature to automatically execute malicious code once a user trusts the repository.
Tappy Admin
3 min read
Jan 24, 2026
163 views
#North Korea hackers
#Visual Studio Code
#VS Code malware
#Contagious Interview campaign
#tasks.json abuse
#malicious repositories
#developer targeting
#Jamf
#cybersecurity
#remote code execution
#Node.js malware
#macOS malware
#GitHub
#GitLab
#fake technical interview
#C2 server
#information stealer
#command injection
#DevSecOps
Read More