logo

Solidity devs targeted again: Malicious VS Code extension drops ScreenConnect-based remote access trojan (RAT)

ID: fc7f66e1-358f-5e3b-8aa6-5842f0d2f2b3

STIX ID: report--fc7f66e1-358f-5e3b-8aa6-5842f0d2f2b3

Feed Name: Checkmarx Zero

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-27

Author: Daniel Miranda

...
...

Checkmarx Zero reported a malicious impersonator VS Code extension (publisher juanblan281, display name using zero-width characters) that executed an obfuscated loader on startup to install a ScreenConnect remote-access tool on Windows and a Python reverse shell with LaunchAgent/systemd persistence on macOS/Linux; the report includes decoded payloads, IOCs (URLs, MSI hash, dropped file paths), timeline of publication and takedown, and recommended containment and hunting steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.