Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS Code) to deliver malware. The campaigns, tracked as UNK_DeadDrop and linked to the Contagious Interview cluster (aka Famous Chollima, HexagonalRodent, Void Dokkaebi), target finance, cryptocurrency, education, and technology sectors.
According to Proofpoint, the UNK_DeadDrop campaign uses phishing emails with links to actor-controlled GitHub repositories hosting malicious scripts. These scripts execute cross-platform malware for macOS, Linux, and Windows, including the open-source Go framework Overlord. A key technique involves VS Code projects that use the ‘runOn: folderOpen’ method to trigger malicious code without user interaction. Over 250 emails were sent to nearly 100 organizations, with 75% in the U.S.
Yeeth Security also discovered three malicious VS Code extensions on the official marketplace—’ByteBinTools.jupyter-powerdev-2026.6.8.vsix’, ‘ToolCraft.jupyter-powertools-3.21.0.vsix’, and ‘OLDev.markdown-mode-devtools-2.1.0.vsix’—disguised as Jupyter Notebook tools but acting as multi-stage backdoors using SharePoint for C2 via Microsoft Graph API.
Additional campaigns include malicious npm packages like ‘redeem-onchain-sdk’, ‘nicegui’, and ‘period-newline’ delivering info-stealers; the TaskJacker campaign dropping malicious VS Code task files; and the use of Git hooks and compromised Packagist packages. The threat actor has also deployed variants of BeaverTail, InvisibleFerret, OtterCookie, and Cabbage RAT, targeting cryptocurrency wallets and credentials. Expel reported $12 million in cryptocurrency theft from 2,726 infected developers in early 2026.
CVEs: CVE-2026-11645
Attack groups: Contagious Interview, Famous Chollima, HexagonalRodent, Void Dokkaebi, UNK_DeadDrop, Lazarus Group, BlueNoroff, Sapphire Sleet, UNC1069
Malware: Overlord, BeaverTail, InvisibleFerret, OtterCookie, Cabbage RAT, CageyChameleon, DEV#POPPER RAT, ClipViper, PromptMink, Mach-O Man
Companies: Proofpoint, Yeeth Security, OpenSourceMalware, Trend Micro, Microsoft, Panther, Expel, S2 Grupo LAB52
Products: Microsoft Visual Studio Code, Cursor, GitHub, npm, Microsoft Graph API, SharePoint, Packagist
Original source: thehackernews.com