Beware of Weaponized VS Code Extension Named ClawdBot Agent that Deploys ScreenConnect RAT
ID: 3569b122-ba98-56d6-ad31-2e39c6f8a778
STIX ID: report--3569b122-ba98-56d6-ad31-2e39c6f8a778
Feed Name: cybersecurityNews.com
A fake VS Code extension named “ClawdBot Agent” (discovered 2026-01-27) posed as an AI assistant but contained a dropper that installed malware on Windows. The payload deployed a preconfigured ScreenConnect client that connected to attacker-controlled servers (meeting.bulletmailer.net:8041) and used a Rust DLL to fetch backup payloads from Dropbox disguised as a Zoom update, providing persistent remote access. The extension integrated with legitimate AI providers to appear trustworthy, executed on VS Code startup, and included multiple fallback mechanisms; Microsoft removed the extension after detection and analysts advise immediate removal, blocking of infrastructure, and rotating API keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
