news.mlab.sh
Back to the feed
threat-intel

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

High
Image: The Hacker News
Summary

A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised as a font file, targeting Windows, Linux, and macOS systems. The campaign, attributed to North Korea's OpenSourceMalware team, utilizes a multi-stage loader and a Socket.io backdoor to steal sensitive data, including credentials, browser information, and cryptocurrency wallets, while also impacting the Go ecosystem with similar compromised packages.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.