Breach404
Back to Insights
Cybersecurity2 min readJune 29, 2026

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Attackers have compromised legitimate npm and Go package repositories to distribute malware that uses VS Code task automation to silently install Python-based information-stealing malware on developer machines. You should immediately audit your organizati

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free