logo

VS Code extensions contain trojan-laden image

ID: 65b77383-7f3c-5e8a-9315-f8375b5edf34

STIX ID: report--65b77383-7f3c-5e8a-9315-f8375b5edf34

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2025-12-10

Date Updated: 2026-04-29

Author: Petar Kirhmajer

...
...

ReversingLabs uncovered a campaign of 19 malicious VS Code extensions (active since February 2025) that weaponized a popular npm dependency (path-is-absolute) and abused bundled dependency folders to conceal a base64-reversed JavaScript dropper and two malicious binaries—one hidden inside a fake PNG archive and executed via cmstp.exe, the other a Rust trojan. The campaign demonstrates supply-chain abuse of pre-packaged extension dependencies to evade detection; ReversingLabs detected the binaries with ML, published IoCs, and reported the extensions to Microsoft, recommending auditing extensions and dependencies and using security tooling to reduce exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.