CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

North Korean Hackers Weaponize VS Code and Developer Tools in Supply Chain Attacks

June 25, 2026

Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS Code) to deliver malware. The campaigns, tracked as UNK_DeadDrop and linked to the Contagious Interview cluster (aka Famous Chollima, HexagonalRodent, Void Dokkaebi), target finance, cryptocurrency, education, and technology sectors.

According to Proofpoint, the UNK_DeadDrop campaign uses phishing emails with links to actor-controlled GitHub repositories hosting malicious scripts. These scripts execute cross-platform malware for macOS, Linux, and Windows, including the open-source Go framework Overlord. A key technique involves VS Code projects that use the ‘runOn: folderOpen’ method to trigger malicious code without user interaction. Over 250 emails were sent to nearly 100 organizations, with 75% in the U.S.

Yeeth Security also discovered three malicious VS Code extensions on the official marketplace—’ByteBinTools.jupyter-powerdev-2026.6.8.vsix’, ‘ToolCraft.jupyter-powertools-3.21.0.vsix’, and ‘OLDev.markdown-mode-devtools-2.1.0.vsix’—disguised as Jupyter Notebook tools but acting as multi-stage backdoors using SharePoint for C2 via Microsoft Graph API.

Additional campaigns include malicious npm packages like ‘redeem-onchain-sdk’, ‘nicegui’, and ‘period-newline’ delivering info-stealers; the TaskJacker campaign dropping malicious VS Code task files; and the use of Git hooks and compromised Packagist packages. The threat actor has also deployed variants of BeaverTail, InvisibleFerret, OtterCookie, and Cabbage RAT, targeting cryptocurrency wallets and credentials. Expel reported $12 million in cryptocurrency theft from 2,726 infected developers in early 2026.

CVEs: CVE-2026-11645

Attack groups: Contagious Interview, Famous Chollima, HexagonalRodent, Void Dokkaebi, UNK_DeadDrop, Lazarus Group, BlueNoroff, Sapphire Sleet, UNC1069

Malware: Overlord, BeaverTail, InvisibleFerret, OtterCookie, Cabbage RAT, CageyChameleon, DEV#POPPER RAT, ClipViper, PromptMink, Mach-O Man

Companies: Proofpoint, Yeeth Security, OpenSourceMalware, Trend Micro, Microsoft, Panther, Expel, S2 Grupo LAB52

Products: Microsoft Visual Studio Code, Cursor, GitHub, npm, Microsoft Graph API, SharePoint, Packagist