Hijacked npm and Go Packages Deploy Python Infostealer via VS Code Tasks
Threat actors have compromised legitimate npm and Go packages to deliver a sophisticated Python-based infostealer that exploits Visual Studio Code’s task automation system. The malware hijacks VS Code’s tasks.json configuration to execute malicious payloads silently when developers open infected pro