A new playground: Malicious campaigns proliferate from VSCode to npm
ID: 79c1b25e-5e5b-5e20-9608-18b16a62ab64
STIX ID: report--79c1b25e-5e5b-5e20-9608-18b16a62ab64
Feed Name: ReversingLabs Blog
ReversingLabs researchers tracked a campaign that distributed downloader malware through malicious Visual Studio Code extensions and an associated npm package (etherscancontracthandler). The malicious artifacts used obfuscated JavaScript to fetch second-stage payloads from shared domains, impersonated legitimate tools (including crypto tooling and Zoom), and exhibited fabricated install counts and reviews; while VSCode Marketplace removals occurred, the actor expanded to npm, increasing potential supply-chain exposure. The report lists IOCs, notes the npm package had ~350 downloads, and recommends preapproval, validation, and regular security assessments of IDE plugins and dependencies to mitigate development-environment compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
