logo

Silent Intrusion: VS Code Exploit For Unauthorized Access

ID: ef6027b4-807d-5f4d-96e1-3744aafaf421

STIX ID: report--ef6027b4-807d-5f4d-96e1-3744aafaf421

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2024-10-18

Date Updated: 2026-07-17

...
...

Cyble Research and Intelligence Labs uncovered a sophisticated campaign where a malicious .LNK installer silently deploys an embedded Python runtime and an obfuscated update.py that installs/uses the VSCode CLI to create remote tunnels authenticated via GitHub device activation codes. The malware achieves persistence by creating a scheduled task (MicrosoftHealthcareMonitorNode) that can run with SYSTEM privileges, collects system and user data, exfiltrates information (including the activation code) to a C2 at requestrepo.com, and enables remote file access and command execution; the report includes SHA-256 hashes and URLs as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.