North Korean hackers weaponise VS Code tasks.json to steal credentials from developers
Open a project folder in VS Code, click "Trust," and North Korean malware executes instantly. Sophos documents how NICKEL ALLEY weaponised tasks.json to target crypto and Web3 developers through fake job interviews. The technique has been active since December 2025.
Read more →