logo

Code highlighting with Cursor AI for $500,000

ID: 0cbadeb1-251b-53c9-bac4-e3f39e4190bb

STIX ID: report--0cbadeb1-251b-53c9-bac4-e3f39e4190bb

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-07-10

Date Updated: 2026-04-29

Author: Georgy Kucherin

...
...

Kaspersky investigated a June 2025 incident where a malicious Solidity extension in the Open VSX registry (and subsequent copycat packages) delivered PowerShell-based loaders that installed ScreenConnect remote access and deployed a VMDetector steganographic loader, Quasar RAT, and a credential/crypto wallet stealer; the campaign targeted blockchain developers, resulted in a confirmed theft (~$500k) from one victim, and included multiple network and file indicators (URLs, IP 144.172.112.84, JS hashes) and evidence of repeated malicious packages leveraging search-ranking and homograph tricks to increase installs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.