logo

fast-draft Open VSX Extension Compromised by BlokTrooper

ID: fd6598a1-e8ed-50b5-8717-ea73a266dae0

STIX ID: report--fd6598a1-e8ed-50b5-8717-ea73a266dae0

Feed Name: Aikido Security's Blog

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-07-24

...
...

The KhangNghiem.fast-draft Open VSX extension (≈26k downloads) contained multiple non-contiguous malicious releases that used a GitHub-hosted downloader to pull a second-stage Node payload which launches four detached modules — a Socket.IO RAT, a browser and crypto-wallet stealer, a recursive file exfiltrator, and a clipboard monitor — exfiltrating data to C2 infrastructure at 195.201.104.53; alternating clean and malicious versions indicate likely publisher compromise and provide concrete IOCs and affected versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.