CSIDB logo
Incident

DataStax

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 07:18

Linked entities

Victim
DataStax
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
2023
Discovered
Mar 2026
Disclosed
Apr 2026
Resolved
Pending

Summary

A North Korean threat actor tracked as Void Dokkaebi (also known as Famous Chollima) has been using fake job offers to lure developers into cloning malicious repositories that contain harmful Visual Studio Code tasks and injected code. When a developer opens the project in VS Code and accepts the workspace trust prompt, the malicious task runs automatically, and committing the code to GitHub hides the .vscode folder, turning the repository into a Trojan horse that infects anyone who later clones and opens it, creating a self‑propagating chain. This technique has led to hundreds of compromised code bases, including repositories belonging to the data management company DataStax and the Java application provider Neutralinojs, spreading remote access Trojans and other malware through the software supply chain.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The campaign tracked by Trend Micro as Void Dokkaebi, also known as Famous Chollima, involves North Korean actors using fake job offers to target software developers. Attackers pose as recruiters from cryptocurrency and artificial intelligence firms and invite victims to participate in a technical assessment during a fabricated interview. As part of the assessment, victims are asked to clone a code repository and review or run its contents. The attackers embed malicious Visual Studio Code workspace tasks and injected code that execute automatically when the victim opens the project in VS Code and accepts the workspace trust prompt. Once executed, the malicious code can install remote access Trojans and other malware, and it hides the .vscode folder by default when the victim commits the code to GitHub. This hidden folder acts as a Trojan horse, so any subsequent developer who clones the repository and opens it in VS Code receives a trust prompt that, if accepted, repeats the infection cycle. Each compromised developer thus seeds new repositories with the infection vector, enabling a self‑propagating chain across the software supply chain. In a single month, Trend Micro identified more than 750 infected code repositories, over 500 malicious VS Code task configurations, and 101 instances of the commit‑tampering tool used by the threat group.

Among the affected repositories, Trend Micro reported that repositories belonging to the data management company DataStax were found carrying infection markers. Repositories of the Java application provider Neutralinojs were also identified as containing similar markers. The presence of these markers indicates that the malicious VS Code task infrastructure had been introduced into those code bases. Trend Micro’s report, published in April 2026, detailed the campaign’s evolution since at least 2023 and its expansion beyond initial targets. The report highlighted the use of fake job lures as a conduit for supply‑chain compromise affecting multiple organizations.

Sources

Sources available to members: 1 source.

CSIDB