logo

Malicious VS Code Extension Impersonating “Material Icon Theme” Found in Marketplace

ID: ea5551d9-e3c6-5985-a89f-588fb21b121b

STIX ID: report--ea5551d9-e3c6-5985-a89f-588fb21b121b

Feed Name: Nextron Systems

Threat Score
75/100

Date Published: 2025-11-28

Date Updated: 2026-04-28

Author: Marius Benthin

...
...

A malicious VS Code extension (icon-theme-materiall v5.29.1) was discovered on the Microsoft Marketplace containing two Rust implants (Windows PE and macOS Mach-O). The report provides sample hashes, YARA rules that matched, links to related GlassWorm activity, and notes the extension remained online after reporting to Microsoft; a full technical analysis of the implants (including C2 via Solana wallet and fallback channels) is available in a follow-up post.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.