logo

A new playground: Malicious campaigns proliferate from VSCode to npm

ID: 79c1b25e-5e5b-5e20-9608-18b16a62ab64

STIX ID: report--79c1b25e-5e5b-5e20-9608-18b16a62ab64

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2024-12-18

Date Updated: 2026-04-29

Author: [email protected] (Lucija Valentić)

...
...

ReversingLabs researchers tracked a campaign that distributed downloader malware through malicious Visual Studio Code extensions and an associated npm package (etherscancontracthandler). The malicious artifacts used obfuscated JavaScript to fetch second-stage payloads from shared domains, impersonated legitimate tools (including crypto tooling and Zoom), and exhibited fabricated install counts and reviews; while VSCode Marketplace removals occurred, the actor expanded to npm, increasing potential supply-chain exposure. The report lists IOCs, notes the npm package had ~350 downloads, and recommends preapproval, validation, and regular security assessments of IDE plugins and dependencies to mitigate development-environment compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.