TasksJacker is a DPRK-linked malware and credential-harvesting activity cluster associated with the Lazarus Group’s broader developer-targeting operations. It is closely linked to the Contagious Interview intrusion set and to the later PolinRider campaign, which initially weaponized credentials stolen through TasksJacker. The activity has been observed in overlap with PolinRider on compromised developer repositories, indicating operational continuity or adjacent sub-campaigning within the same North Korean ecosystem. TasksJacker is used to compromise software developers and steal credentials from their environments, enabling follow-on supply-chain abuse and account takeover. Reporting links it to malicious artifacts embedded in developer tooling workflows, including abuse of Visual Studio Code task configurations. In later related operations, stolen access was leveraged to compromise GitHub repositories, inject obfuscated JavaScript into project configuration files, and propagate malicious changes through open-source development ecosystems. This places TasksJacker within a broader DPRK tradecraft pattern focused on developer impersonation, repository compromise, credential theft, persistence in development environments, and downstream software supply-chain exploitation. The cluster is associated with campaigns targeting individual developers, especially job-seeking developers, rather than only enterprise organizations. Its role appears to be primarily enabling initial compromise and credential theft that support subsequent post-compromise actions by related Lazarus-linked operations. Known associated campaign names include Contagious Interview and PolinRider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Credential-harvesting operation linked in the article as a precursor phase to PolinRider.
Referenced as a connected Lazarus activity cluster whose stolen credentials and .vscode/tasks.json payloads overlap with PolinRider infections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.