logo

Malicious VSCode Marketplace extensions hid trojan in fake PNG file

ID: cd6865ff-f320-5a34-b211-b3603e17e87a

STIX ID: report--cd6865ff-f320-5a34-b211-b3603e17e87a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A campaign active since February distributed 19 malicious VSCode Marketplace extensions that included a bundled node_modules folder with modified dependencies (e.g., path-is-absolute or @actions/io). The injected code decodes an obfuscated JavaScript dropper from a ‘lock’ file and an archive masquerading as banner.png that contains two malicious binaries — a living-off-the-land binary (cmstp.exe) and a Rust-based trojan — potentially enabling supply-chain compromise of developer environments; ReversingLabs reported the extensions and they have been removed, but affected users should scan for signs of infection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.