logo

Malicious pull request infects VS Code extension

ID: d250f940-d845-5c46-871c-742edeb896c9

STIX ID: report--d250f940-d845-5c46-871c-742edeb896c9

Feed Name: ReversingLabs Blog

Threat Score
72/100

Date Published: 2025-07-08

Date Updated: 2026-04-29

Author: Petar Kirhmajer

...
...

ReversingLabs discovered a supply-chain compromise of the ETHcode VS Code extension where a throwaway GitHub account submitted a PR that added a carefully named malicious dependency ('keythereum-utils'). The obfuscated dependency is invoked via require(), spawns a hidden PowerShell, and downloads a second-stage batch script likely intended to steal cryptocurrency or otherwise compromise developer systems; the extension was removed from the VS Code Marketplace and a clean version was published, while RL published IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.