Back to all lessons
Awareness Lessons
3 months ago

Hijacked npm & Go Packages Abuse VS Code Tasks to Deliver Python Infostealer

Attackers compromised legitimate npm and Go packages to inject malicious code that exploits VS Code's task automation feature, silently executing a Python infostealer when a developer opens an affected project folder. This is a classic supply chain attack where developers inherently trust packages from public registries, making them a high-value target for credential and data theft. The technique is particularly dangerous because it bypasses typical npm lifecycle script scrutiny by hiding execution in IDE configuration files like `.vscode/tasks.json`. This matters because developer machines often hold privileged credentials, source code, API keys, and access to production environments — making them a critical pivot point for broader compromise.

Tactical Insight

Immediate actions

  • Audit all project `.vscode/tasks.json` and equivalent IDE configuration files for unexpected or obfuscated commands.
  • Pin all npm and Go package dependencies to verified, specific versions and validate them against known-good checksums (e.g., using lockfiles and integrity hashes).
  • Scan developer environments for unexpected Python processes or network connections indicative of infostealer activity.

Long-term improvements

  • Implement a software composition analysis (SCA) tool in CI/CD pipelines to automatically flag newly introduced or modified third-party packages before they reach developer machines.
  • Establish an internal, vetted package mirror or allowlist to prevent direct consumption of untrusted public registry packages.
  • Apply least-privilege principles to developer workstations to limit what scripts and processes can execute or access sensitive credential stores.

Detection measures

  • Configure endpoint detection and response (EDR) tools to alert on IDE processes spawning unexpected child processes, especially Python interpreters.
  • Enable and centrally collect logs from developer endpoints, focusing on new process creation, outbound network connections, and file access in credential storage paths.
  • Subscribe to security advisories from npm and Go module security feeds (e.g., GitHub Advisory Database, OSV) to receive timely notifications of hijacked packages.