#TasksJacker

Incident/Operation

2026-03-31 • TasksJacker: Latest DPRK Attack Skips the Fake Interview and Goes Straight to Compromising GitHub Users

TasksJacker is a 2026 Lazarus Group campaign that automates compromise of software developers by injecting malicious Visual Studio Code task configuration into GitHub repositories. The task can execute when a developer opens the repository, bypassing the direct fake-interview social engineering used by Contagious Interview and harvesting credentials that enable further repository compromise. This technique helped seed the related PolinRider campaign, which propagated malicious code across thousands of projects, and represents a scalable software-supply-chain attack against developer workstations and source-control accounts.

Tagged Reports

« Back