Hijacked npm and Go packages use VS Code tasks to deliver Python infostealer
Source headline: Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Intelligence Summary
JFrog reports a campaign that abuses hijacked npm packages alongside malicious Go components. The goal is to deliver a Python-based information stealer that runs on Windows, Linux, and macOS systems. The payload deployment is orchestrated via VS Code task mechanisms to reduce reliance on common npm execution paths. This approach may help the malware remain compatible with newer npm security hardenings. Users should review dependencies from npm for unexpected behavior and tighten controls around package provenance and execution.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.