logo

Threat Actors Using Malicious VSCode Extension to Deploy Anivia Loader and OctoRAT

ID: e71d0998-8a3b-589c-a267-966ce957faf7

STIX ID: report--e71d0998-8a3b-589c-a267-966ce957faf7

Feed Name: cybersecurityNews.com

Threat Score
82/100

Date Published: 2025-12-04

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A fake Visual Studio Code extension posing as the Prettier formatter briefly appeared in the VSCode Marketplace and, once installed, fetched an obfuscated VBScript dropper from a malicious GitHub repository; that dropper wrote a Base64/AES PowerShell loader which decrypted and executed an intermediate Anivia loader that injected and launched the OctoRAT remote access trojan, enabling persistence, remote control, and theft of browser and wallet data from high-value developer systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.