Sophisticated Malware Lurks In Open VSX Extension With 5,066 Downloads
ID: d00a6c69-6542-5df3-a0ea-67cecb4e4130
STIX ID: report--d00a6c69-6542-5df3-a0ea-67cecb4e4130
Feed Name: GBHackers
A malicious Open VSX VS Code extension impersonating the Angular Language Service amassed ~5,066 downloads before activating an AES-256-CBC encrypted loader that decrypts and evals a payload after a sandbox-evasion delay. The stage-1 payload reads dynamic C2 instructions from a Solana memo (Etherhiding) to retrieve stage-2 code from identified IPs (217.69.11.57, 108.61.208.161), performs environment checks to avoid Russian locales, establishes persistence (hidden Node binary, scheduled task, Registry Run key), and steals developer credentials, npm/GitHub tokens, browser wallets and other sensitive assets before exfiltrating zipped data to remote servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
