Cybersecurity researchers have identified malicious npm and Go packages that exploit Visual Studio Code tasks to deploy the InvisibleFerret Python infostealer on Windows, Linux, and macOS developer systems.
Key Points
- Attackers uploaded two malicious npm packages, "html-to-gutenberg" and "fetch-page-assets," alongside 16 compromised Go packages to distribute malware.
- The infection triggers when a developer opens a project folder in VS Code, executing a hidden task that runs malicious code disguised as a font file.
- The malware uses blockchain transaction data from TronGrid and Aptos to retrieve encrypted payloads, making the command-and-control infrastructure resilient to takedowns.
- The InvisibleFerret backdoor harvests cryptocurrency wallets, browser credentials, Git tokens, and cloud storage metadata, exfiltrating data to a remote server or Telegram bot.
- Security analysts attribute this "Fake Font" campaign to North Korean actors as part of the ongoing "Contagious Interview" operation targeting software developers.