Threats · 91 days ago
Opening an untrusted project in the editor is now enough to hand attackers code execution. The campaign has shifted from generic developer-themed lures to GitHub repositories and VS Code project auto-run, so the normal “open the folder” habit can trigger malware on macOS, Linux, and Windows before anyone treats it as a suspicious file.
Proofpoint now ties more than 250 emails to nearly 100 organizations to UNK_DeadDrop, linked to Contagious Interview. The repos posed as technical assignments or crypto projects, and the payload chain led to Overlord, a malicious VS Code extension, and theft of browser credentials, wallet data, and desktop wallet secrets.
The exposure is broader than email filtering or repo takedown. If the trust shortcut lives in VS Code, Cursor, or similar review workflows, cleaning the repository does not undo the access already gained through the editor itself.
4 sources covering this story
North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
Proofpoint says UNK_DeadDrop sent 250+ phishing emails to nearly 100 firms, using GitHub and VS Code lures to steal credentials and wallet data.
Suspected North Korean actors use fake ‘coding assignments’ to steal crypto
Targets are encouraged to clone Git repositories to their VS Code or Cursor code editors.
Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto
When an unsolicited job offer sounds too good to be true …
North Korean Hackers Use Fake Coding Tasks to Steal Crypto
North Korean actor UNK_DeadDrop targeted developers with fake coding tasks to steal crypto
Part of the PlainSec briefing for 2026-06-16