logo

Open VSX Extension Delivers RAT and Stealer via GitHub Downloader

ID: 152f662a-e7aa-5a0d-8f97-3328cd699a4f

STIX ID: report--152f662a-e7aa-5a0d-8f97-3328cd699a4f

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

A widely downloaded Open VSX extension (fast-draft, ~26k downloads) contained malicious releases that used raw.githubusercontent.com to download and execute platform-specific loaders which unpacked a Node-based second-stage payload. The payload implements a Socket.IO remote-access trojan (remote desktop, input control, screenshots), a browser and crypto-wallet stealer that exfiltrates LevelDB and credential stores, targeted document/secret collection tuned for developer workstations, and continuous clipboard harvesting; infrastructure and active C2 IPs (195.201.104.53 ports 6931/6936/6939) are documented, and version patterns indicate a likely compromised publisher or stolen release token.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.