logo

Python-Based Malware Slithers Into Systems via Legit VS Code

ID: df2619f1-22dc-50a6-94eb-c065766db0b0

STIX ID: report--df2619f1-22dc-50a6-94eb-c065766db0b0

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-10-02

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers from Cyble CRIL uncovered an ongoing Mustang Panda APT campaign that begins with a malicious .lnk file delivering a Python distribution which installs a script that checks for VS Code, deploys the VS Code CLI if needed, and abuses VS Code Remote Tunnels plus GitHub authentication to create a persistent remote tunnel for unauthorized access, data collection, and further malware deployment; the script was initially undetected on VirusTotal and defenders are advised to use behavioral endpoint protections, review scheduled tasks, restrict install permissions, and train users against suspicious files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.