logo

Malicious VSCode Extension Launches Multi-Stage Attack Chain with Anivia Loader and OctoRAT

ID: 9ea78da9-819e-577b-9a35-7fa9ced3cd0e

STIX ID: report--9ea78da9-819e-577b-9a35-7fa9ced3cd0e

Feed Name: Hunt.io Blog

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report details a November 2025 supply-chain attack where a malicious VSCode extension named "prettier-vscode-plus" delivered a multi-stage infection chain (VBScript dropper, PowerShell loader, Anivia loader, and OctoRAT RAT), enabling browser credential and wallet theft, full remote access, persistence via scheduled tasks, privilege escalation (FodHelper UAC bypass), process hollowing into vbc.exe, and a web-based OctoRAT control panel; the analysis includes technical decomposition, MITRE ATT&CK mapping, IOCs (file hashes), and internet-wide C2 fingerprinting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.