🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain ext-checkedin.vercel.app.

Database Entry


IOC ID:1956229
IOC: ext-checkedin.vercel.app
IOC Type :domain
Threat Type :payload_delivery
Malware: ContagiousDrop
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS16509 AMAZON-02
Country:- US
First seen:2026-10-07 10:38:35 UTC
Last seen:2026-10-08 08:47:31 UTC
UUID:30ba8ab2-c237-11f1-bd13-42010aa4000a
Reporter Dethanc
Reward 5 credits from ThreatFox
Tags:ContagiousInterview vscode vscode-tasks-folderOpen
Reference: https://www.threatlocker.com/blog/malicious-vs-code-tasks-json-abuse-enables-multi-stage-infostealer-deployment

Avatar
Dethanc
Stager domains for Contagious Interview attack - interviewee is asked to clone repo that contains tasks.json, which auto-runs code in VSCode. This code harvests local credentials and sends them to these domains, which then respond with additional code to be executed on the compromised machine.