logo

Sophisticated Malware Lurks In Open VSX Extension With 5,066 Downloads

ID: d00a6c69-6542-5df3-a0ea-67cecb4e4130

STIX ID: report--d00a6c69-6542-5df3-a0ea-67cecb4e4130

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-01-30

Date Updated: 2026-04-22

Author: Varshini

...
...

A malicious Open VSX VS Code extension impersonating the Angular Language Service amassed ~5,066 downloads before activating an AES-256-CBC encrypted loader that decrypts and evals a payload after a sandbox-evasion delay. The stage-1 payload reads dynamic C2 instructions from a Solana memo (Etherhiding) to retrieve stage-2 code from identified IPs (217.69.11.57, 108.61.208.161), performs environment checks to avoid Russian locales, establishes persistence (hidden Node binary, scheduled task, Registry Run key), and steals developer credentials, npm/GitHub tokens, browser wallets and other sensitive assets before exfiltrating zipped data to remote servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.