logo

Analysis of the Rust implants found in the malicious VS Code extension

ID: 62bbe2b6-8fed-59e6-8cf9-0aabf7271701

STIX ID: report--62bbe2b6-8fed-59e6-8cf9-0aabf7271701

Feed Name: Nextron Systems

Threat Score
72/100

Date Published: 2025-11-29

Date Updated: 2026-04-28

Author: Nextron Threat Research Team

...
...

This report details a malicious campaign distributing implants via a trojanized VS Code extension that executes Rust implants through a loader (extension.js) and platform native modules, fetches C2 instructions from a Solana blockchain wallet (with a Google Calendar fallback using invisible Unicode to hide the address), and downloads AES-256-CBC encrypted JavaScript payloads; the report includes file hashes, IPs, URLs, and other indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.