North Korea-Linked Hackers Target Developers via Malicious VS Code Projects: Implications for North East India
Evolution of North Korean Cyber Espionage Tactics
A new tactic by North Korean threat actors, linked to the Contagious Interview campaign, has been identified. These actors are now using malicious Microsoft Visual Studio Code (VS Code) projects as lures to deliver a backdoor on compromised endpoints. This activity demonstrates the continued evolution of their tactics, as first discovered in December 2025.
Abuse of VS Code Task Configuration Files
The attack essentially involves instructing prospective targets to clone a repository on GitHub, GitLab, or Bitbucket, and launch the project in VS Code as part of a supposed job assessment. The end goal is to abuse VS Code task configuration files to execute malicious payloads staged on Vercel domains, depending on the operating system on the infected host.
Impact on North East India and Broader India
Given the increasing digitalization and growth of the tech industry in North East India, these types of attacks pose a significant threat. The region's developers and tech companies must stay vigilant and implement robust security measures to protect their systems and data.
Multiple Delivery Methods and Fallback Mechanisms
The attack chain is engineered to fallback to two other methods: installing a malicious npm dependency named "grayavatar" or running JavaScript code that retrieves a sophisticated Node.js controller. This shows that the state-sponsored actors are experimenting with multiple delivery methods to increase the likelihood of success of their attacks.
Implications and Future Threats
These findings indicate that the state-sponsored actors are consistently adapting their tooling and delivery mechanisms to integrate with legitimate developer workflows. This highlights the need for developers and tech companies worldwide, including those in North East India, to stay informed about the latest threats and implement strong security measures to protect their systems and data.
As the tech industry in North East India continues to grow, it is crucial for developers and companies to prioritize cybersecurity. By staying informed, implementing robust security measures, and working together, we can help protect our digital ecosystem from such threats.