logo

Hackers Infiltrate VS Code Marketplace with 19 Malicious Extensions Posing as PNG File

ID: 3a344e0f-91e0-556b-b9fc-d2820159ccf7

STIX ID: report--3a344e0f-91e0-556b-b9fc-d2820159ccf7

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-11

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Security researchers uncovered a coordinated supply-chain malware campaign on the VS Code Marketplace involving 19 malicious extensions that weaponized the popular "path-is-absolute" npm package to conceal a base64/string-reversed JavaScript dropper inside PNG image files; the dropper uses cmstp.exe to deploy two binaries (including a Rust-based trojan) and remained active since February 2025, contributing to a sharp rise in VS Code malware detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.