logo

The obfuscation game: MUT-9332 targets Solidity developers via malicious VS Code extensions

ID: 8d504b76-43fe-57fc-9687-d5e548e65b4e

STIX ID: report--8d504b76-43fe-57fc-9687-d5e548e65b4e

Feed Name: Datadog Security Labs

Threat Score
72/100

Date Published: 2025-05-21

Date Updated: 2026-04-27

...
...

Datadog Security Research identified a multi-stage malware campaign by actor MUT-9332 that trojanized three VS Code extensions aimed at Solidity developers; the extensions delivered PowerShell- and VBScript-based stages that install a malicious Chromium extension and Windows binaries (myau.exe, myaunet.exe) to disable protections, persist via shortcuts and registry, and exfiltrate cryptocurrency wallet credentials and other data. The report documents the full attack flow, obfuscation techniques (including a payload embedded in a public image), defensive evasion measures, hashes and URLs for IOCs, and notes the extensions were removed from the Marketplace after fewer than ~50 installs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.