23pds posted on X. Reports have emerged that individuals associated with North Korea are using deceptive recruitment tactics to lure developers into opening malicious Visual Studio Code projects. These projects, once opened, automatically execute hidden tasks that retrieve JavaScript from Vercel and deploy backdoors, enabling remote code execution. Concerns have been raised as this attack method and its code were reportedly visible on GitHub in the repository 'VSCode-Backdoor' seven months ago, yet it has only recently gained widespread attention.
