← All stories
● Covered by 1 source · 1 reportHigh impact

Hijacked npm and Go Packages Deploy Python Infostealer via VS Code Tasks

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two npm packages, 'html-to-gutenberg' and 'fetch-page-assets' deployed malware.
  • Malware uses VS Code tasks to execute code intentionally designed to bypass security.
  • Attack linked to North Korean activity and the ongoing 'Fake Font' campaign.

Discovery of Hijacked Packages

Cybersecurity researchers discovered two malicious npm packages, 'html-to-gutenberg' and 'fetch-page-assets', which were found to enable the deployment of a Python-based infostealer. These packages, uploaded to npm on May 25, 2026, have since been removed from the registry. The use of hijacked packages represents a significant risk to developers and organizations utilizing these tools.

Exploitation via VS Code

The attack exploits a hidden task in Microsoft Visual Studio Code, named 'eslint-check'. This task is configured to run automatically when the project folder is opened, leading to the execution of arbitrary code. The malware retrieves JavaScript from blockchain data, connects to an attacker's infrastructure, and installs a socket.io backdoor.

Malware Strategy

The payload disguises itself as a font file while executing JavaScript code. This technique aims to circumvent security measures implemented in npm v12. Research from JFrog indicates that the attack's success depends on the workspace being marked as trusted by the developer.

Connection to Ongoing Cyber Activities

This malware deployment is part of a larger campaign linked to North Korean cyber activities, referred to as the 'Fake Font' campaign. The campaign utilizes fraudulent job Interview processes to infiltrate software developer communities, delivering multi-stage load malware that targets sensitive information. Researchers have noted this is a continuation of the 'Contagious Interview' campaign.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Cybersecurity researchers have identified hijacked npm and Go packages that deploy a Python-based infostealer on compromised systems. This method utilizes a concealed VS Code task to execute malware upon opening a project folder, facilitating data theft and persistent access.