logo

Fake AI Assistant: Malicious “ClawdBot” Extension Hides Trojan in VS Code

ID: 48cc8364-d74f-5671-bc7c-432a1bd24319

STIX ID: report--48cc8364-d74f-5671-bc7c-432a1bd24319

Feed Name: securityonline.info

Threat Score
68/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

A malicious VS Code extension impersonating the popular 'ClawdBot' (named “ClawdBot Agent”) was discovered deploying a trojanized payload to Windows systems while appearing as a fully functional AI coding assistant. The dropper used filenames like Lightshot.exe/Lightshot.dll or an Electron bundle (Code.exe), and command-and-control activity was traced to darkgptprivate.com (hosted in Seychelles) with Cloudflare fronting and fallback mechanisms. Microsoft removed the extension after ~21 installs; the incident demonstrates high attacker sophistication and the risk of supply-chain/extension impersonation against developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.