Malicious VSCode extensions on Microsoft's registry drop infostealers
ID: c6b6b9f5-cb51-5522-ab90-585e55dd7718
STIX ID: report--c6b6b9f5-cb51-5522-ab90-585e55dd7718
Feed Name: Bleeping Computer
Two malicious VS Code extensions published as Bitcoin Black and Codo AI (under the developer name 'BigBlack') were found on the Visual Studio Code Marketplace; they used activation events and scripts (PowerShell/batch with curl) to download a legitimate Lightshot executable and a malicious DLL loaded via DLL hijacking to deploy an infostealer named runtime.exe that captures screenshots, credentials, cookies (by launching browsers headlessly), and cryptocurrency wallets, storing data in an '%APPDATA%\Local\Evelyn' directory. Microsoft has since removed the extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
