Malicious VSCode Marketplace extensions hid trojan in fake PNG file
ID: cd6865ff-f320-5a34-b211-b3603e17e87a
STIX ID: report--cd6865ff-f320-5a34-b211-b3603e17e87a
Feed Name: Bleeping Computer
A campaign active since February distributed 19 malicious VSCode Marketplace extensions that included a bundled node_modules folder with modified dependencies (e.g., path-is-absolute or @actions/io). The injected code decodes an obfuscated JavaScript dropper from a ‘lock’ file and an archive masquerading as banner.png that contains two malicious binaries — a living-off-the-land binary (cmstp.exe) and a Rust-based trojan — potentially enabling supply-chain compromise of developer environments; ReversingLabs reported the extensions and they have been removed, but affected users should scan for signs of infection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
