Backdoored Open VSX Extension Used GitHub Downloader to Deploy RAT and Stealer
ID: cd6f0a20-3a10-54bf-a658-be7faee04839
STIX ID: report--cd6f0a20-3a10-54bf-a658-be7faee04839
Feed Name: cybersecurityNews.com
**Supply-chain malware in an Open VSX extension:** The 'fast-draft' extension (KhangNghiem) contained malicious code in specific releases that downloaded and executed a second-stage payload from raw.githubusercontent.com/BlokTrooper, deploying a RAT and infostealer that exfiltrated credentials, crypto wallets, local files, and clipboard data to C2 195.201.104.53 (ports 6931, 6936, 6939); approximately 26k+ downloads may be exposed and admins should remove impacted versions and rotate secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
