Post #3075960
2026-01-22 22:31 UTC
Thanks to @cxiao@infosec.exchange for highlighting these:
https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/
https://opensourcemalware.com/blog/contagious-interview-vscode
.. I do know that the version of tokenlinux.sh I retrieved also downloads node and executes something with it.
Replies (1)
-
@cxiao@infosec.exchange 2026-01-22 22:58
@mushu@social.troll.academy np, glad it didn't get you in this case and thanks for writing it up to warn others!