Developer Tools Now Deliver Cross-Platform Malware
Opening an untrusted project in the editor is now enough to hand attackers code execution. The campaign has shifted from generic developer-themed lures to GitHub repositories and VS Code project auto-run, so the normal “open the folder” habit can trigger malware on macOS, Linux, and Windows before anyone treats it as a suspicious file.
Proofpoint now ties more than 250 emails to nearly 100 organizations to UNK_DeadDrop, linked to Contagious Interview. The repos posed as technical assignments or crypto projects, and the payload chain led to Overlord, a malicious VS Code extension, and theft of browser credentials, wallet data, and desktop wallet secrets.
The exposure is broader than email filtering or repo takedown. If the trust shortcut lives in VS Code, Cursor, or similar review workflows, cleaning the repository does not undo the access already gained through the editor itself.