Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT
ID: e71d0998-8a3b-589c-a267-966ce957faf7
STIX ID: report--e71d0998-8a3b-589c-a267-966ce957faf7
Feed Name: cybersecurityNews.com
A fake Visual Studio Code extension posing as the Prettier formatter briefly appeared in the VSCode Marketplace and, once installed, fetched an obfuscated VBScript dropper from a malicious GitHub repository; that dropper wrote a Base64/AES PowerShell loader which decrypted and executed an intermediate Anivia loader that injected and launched the OctoRAT remote access trojan, enabling persistence, remote control, and theft of browser and wallet data from high-value developer systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
