Code highlighting with Cursor AI for $500,000
ID: 0cbadeb1-251b-53c9-bac4-e3f39e4190bb
STIX ID: report--0cbadeb1-251b-53c9-bac4-e3f39e4190bb
Feed Name: Securelist by Kaspersky
Kaspersky investigated a June 2025 incident where a malicious Solidity extension in the Open VSX registry (and subsequent copycat packages) delivered PowerShell-based loaders that installed ScreenConnect remote access and deployed a VMDetector steganographic loader, Quasar RAT, and a credential/crypto wallet stealer; the campaign targeted blockchain developers, resulted in a confirmed theft (~$500k) from one victim, and included multiple network and file indicators (URLs, IP 144.172.112.84, JS hashes) and evidence of repeated malicious packages leveraging search-ranking and homograph tricks to increase installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
