Home / Jun 30, 2026 / Story
0
#10 The Hacker News general June 29, 2026 at 05:36 UTC

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

By [email protected] (The Hacker News)

AI Summary

JFrog researchers uncovered two hijacked npm packages and a cluster of Go packages engineered to deliver a Python-based infostealer on Windows, Linux, and macOS by exploiting VS Code task execution rather than npm lifecycle scripts — a technique apparently designed to bypass npm v12's new security hardenings. The attack targets developer environments directly through the software supply chain, making it particularly dangerous for organizations that trust internal build pipelines. Security teams should audit VS Code task configurations and monitor for unexpected Python process spawning in CI/CD environments.

Relevance score: 76.0/100

# More from June 30