AUTO-UPDATED

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Cybersecurity researchers have identified malicious npm and Go packages that exploit Visual Studio Code tasks to deploy the InvisibleFerret Python infostealer on Windows, Linux, and macOS developer systems.

Key Points

  • Attackers uploaded two malicious npm packages, "html-to-gutenberg" and "fetch-page-assets," alongside 16 compromised Go packages to distribute malware.
  • The infection triggers when a developer opens a project folder in VS Code, executing a hidden task that runs malicious code disguised as a font file.
  • The malware uses blockchain transaction data from TronGrid and Aptos to retrieve encrypted payloads, making the command-and-control infrastructure resilient to takedowns.
  • The InvisibleFerret backdoor harvests cryptocurrency wallets, browser credentials, Git tokens, and cloud storage metadata, exfiltrating data to a remote server or Telegram bot.
  • Security analysts attribute this "Fake Font" campaign to North Korean actors as part of the ongoing "Contagious Interview" operation targeting software developers.

Why it Matters

This campaign highlights a sophisticated supply chain risk where attackers leverage trusted development environments and IDE features to bypass traditional security filters. Developers and organizations must audit their dependencies and IDE configurations to prevent unauthorized access to sensitive credentials and proprietary source code.
Internet Published by info@thehackernews.com (The Hacker News)
Read original