threat-intel Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer A sophisticated cyberattack has been uncovered involving hijacked npm and Go packages designed to deploy a Python-based information stealer. Attackers leveraged a VS Code task trigger to execute malicious code disguised as a font file, targeting Windows, Linux, and macOS systems. The campaign, attributed to North Korea… The Hacker News · Jun 29, 2026 High KPvscodenpmfont-file