Proofpoint reports that North Korea-linked hackers are developing phishing attacks targeting developers through themes such as recruitment and code review, with targets spanning nearly 100 organizations in finance, crypto, education, technology, and more.


Attackers guide victims via email to clone malicious GitHub repositories and open the project in VS Code or Cursor, triggering cross-platform malicious code execution.
Proofpoint has named this activity UNK_DeadDrop, stating it uses a VS Code project "folderOpen auto-execute" technique and installs malicious extensions disguised as Google services to steal browser wallet extensions, desktop wallets, credentials, and other data. (The Hacker News)
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
Add a comment
Add a comment
GateUser-26374bb4
· 2h ago
Now even VS Code is no longer secure; developers are having a tough time.
View OriginalReply0
TacoTreasury
· 2h ago
This technique is too covert; who would think that folderOpen executes automatically?
View OriginalReply0
AutumnTranquility
· 2h ago
North Korean hackers targeting crypto wallets, this is way too targeted.
View OriginalReply0
GateUser-470bc925
· 2h ago
Be careful with GitHub repositories as well; you need to audit them before cloning.
View OriginalReply0
  • Pinned