gitlab

How to detect and prevent Contagious Interview IDE attacks (opens in new tab)

Contagious Interview attacks abuse VS Code’s automated tasks to execute malware when victims open a malicious repository and trust its workspace. GitLab developed low-level EDR detections around node-pty’s spawn-helper, allowing it to identify hidden background process execution while avoiding normal interactive developer activity. The article recommends combining runtime detection with IDE configuration hardening.

The Contagious Interview Attack Path

  • North Korean threat actors use fake job interviews to persuade targets to download and review malicious code repositories.
  • Repositories can include a .vscode/tasks.json file configured to run automatically when the folder opens.
  • After the victim grants workspace trust, the task executes without obvious interaction.
  • Example payloads:
    • Detect the operating system.
    • Download a platform-specific second-stage payload.
    • Pipe it directly into bash, sh, or cmd using patterns such as curl | bash.
  • Resulting malware may steal passwords and cryptocurrency, deploy infostealers, and establish persistence for abuse of corporate access.

Low-Level Detection with spawn-helper

  • GitLab looked below the VS Code layer because similar attacks can affect VS Code forks and other Node- or Electron-based IDEs.
  • VS Code uses the popular node-pty library to launch subprocesses.
  • node-pty.spawn() invokes a spawn-helper binary, which becomes a child process of the Node application.
  • This makes spawn-helper a useful operating-system-level signal for background task execution.

Reducing False Positives

  • GitLab used Purple Team exercises to reproduce the attack and reviewed EDR telemetry.
  • Background VS Code tasks use spawn-helper, while foreground interactive processes such as the integrated terminal use a Code Helper binary.
  • Detections can therefore focus on processes launched invisibly, without user interaction.
  • GitLab further tuned alerts to identify suspicious commands such as background curl | <shell> execution rather than flagging every automated task.
  • The resulting detection produced no false positives despite widespread VS Code usage internally.

Additional Prevention Measures

  • Runtime EDR monitoring is only one layer of defense.
  • Organizations can proactively harden their fleets by deploying global VS Code configuration that disables automatic task execution.
  • Combining IDE restrictions with process telemetry and behavioral detection provides broader protection against malicious repository-based attacks.

Organizations should disable automatic task runs where practical and monitor low-level subprocess behavior, especially invisible spawn-helper executions that download or pipe remote content into a shell.