fast-draft Open VSX Extension Compromised by BlokTrooper
ID: fd6598a1-e8ed-50b5-8717-ea73a266dae0
STIX ID: report--fd6598a1-e8ed-50b5-8717-ea73a266dae0
Feed Name: Aikido Security's Blog
The KhangNghiem.fast-draft Open VSX extension (≈26k downloads) contained multiple non-contiguous malicious releases that used a GitHub-hosted downloader to pull a second-stage Node payload which launches four detached modules — a Socket.IO RAT, a browser and crypto-wallet stealer, a recursive file exfiltrator, and a clipboard monitor — exfiltrating data to C2 infrastructure at 195.201.104.53; alternating clean and malicious versions indicate likely publisher compromise and provide concrete IOCs and affected versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
