Malicious Microsoft VSCode extensions target devs, crypto community
ID: be401ce5-d345-5dbe-bd81-a7df7aedd4e0
STIX ID: report--be401ce5-d345-5dbe-bd81-a7df7aedd4e0
Feed Name: Bleeping Computer
Threat Score
Researchers discovered a campaign of 18 malicious VSCode extensions (and an associated npm package) that impersonated legitimacy with fake reviews and downloads, then deployed obfuscated downloader code to retrieve AES-encrypted CMD/PowerShell payloads from suspicious domains; secondary payloads were observed on test systems and some dropped binaries were flagged by multiple antivirus engines, with SHA1 indicators published to help detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
